Skip to content

feat(delegation): validate batch task quality before spawning children - #81141

Merged
teknium1 merged 1 commit into
mainfrom
borrow/delegate-batch-validation
Aug 7, 2026
Merged

teknium1 merged 1 commit into
mainfrom
borrow/delegate-batch-validation

Conversation

@teknium1

@teknium1 teknium1 commented Aug 7, 2026

Copy link
Copy Markdown
Collaborator

Rejects malformed tasks=[...] batches before any child spawns: exact-duplicate goals, placeholder goals (bare TODO, 'task N', unexpanded template markers, <10 chars), and 1-task batches (error points at the single goal form). Batch-only — the single-goal form is exempt by design. Errors tell the model exactly how to fix the call. Tool schema unchanged. Existing tests with terse batch goals updated to the new contract. Inspired by: MoonshotAI/kimi-code agent-swarm.md validation rules (MIT)

Infographic

delegate-batch-validation

Reject malformed tasks=[...] batches before any child agent is spawned:

- exact-duplicate goals (case/whitespace-normalized), error names both
  task indices
- placeholder goals: bare 'TODO', bare 'task N', unexpanded <...> or
  {...} template markers, or goals shorter than 10 chars after strip
- 1-task batches, with an error pointing the model at the single
  `goal` form instead

All checks are batch-only — the single-goal form is exempt by design
(short goals like goal="test" are valid there). Error strings are
actionable: each tells the model exactly how to fix the call.

Tool schema is unchanged (byte-stable); validation is runtime-only in
the existing batch-validation region.

Existing tests using terse batch goals ("A"/"B"/"C") updated to
realistic distinct goals per the new contract.

Inspired by: MoonshotAI/kimi-code agent-swarm.md validation rules (MIT)
@github-actions

github-actions Bot commented Aug 7, 2026 •

Copy link
Copy Markdown

૮ >ﻌ< ა ci review

ran on 250e019

⚠️ Warnings

OSV vulnerability scan · View job

50 known vulnerabilities found in pinned dependencies.

How to fix:

Review the findings in the Security tab. Update the affected dependencies if a patched version is available.

@teknium1
teknium1 merged commit 94bc319 into main Aug 7, 2026
43 checks passed
@teknium1
teknium1 deleted the borrow/delegate-batch-validation branch August 7, 2026 15:58
teknium1 added a commit that referenced this pull request Aug 7, 2026
The batch quality gate (#81141) now rejects 1-task batches before
schema coercion runs; exercise schema rejection with a valid batch.
teknium1 added a commit that referenced this pull request Aug 7, 2026
The batch quality gate (#81141) now rejects 1-task batches before
schema coercion runs; exercise schema rejection with a valid batch.
teknium1 added a commit that referenced this pull request Aug 8, 2026
Four fix-forwards from the adversarial post-merge audit of the Aug 7
unreviewed merge batch:

- estop (#81148): is_engaged() now fails SAFE (engaged) on stat errors;
  the gateway estop gate lets recognized slash commands and replies owned
  by in-flight work (update prompts, clarify, slash-confirm, tool
  approvals, running sessions) through instead of consuming them; new
  gateway /pause [reason|off] command gives messaging-only operators an
  in-band engage/resume path (busy_policy=dispatch so it works mid-run).
- cron monitor mode (#81138): execution-mode invariants (monitor x
  no_agent, monitor_script x monitor_url, no_agent-requires-script) now
  have ONE owner (_validate_job_mode_invariants) called from BOTH
  create_job and update_job, so the create-time invariant can no longer
  be silently violated through the update door.
- cron notepad (#81139): remove_job now clears the job's notepad rows
  (clear_notepad was dead code -> orphaned KV state forever); clear is
  best-effort and no-ops without creating notepad.db.
- delegation batch gate (#81141): template-marker regex narrowed to
  multi-word placeholder shapes only (<feature name>, {file_path}) so
  generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string
  style no longer reject legitimate batches; duplicate-goal rejection
  removed (best-of-N fan-outs are legitimate).
sliamh11 added a commit to sliamh11/hermes-agent that referenced this pull request Aug 9, 2026
…ced reload (#2)

* Inspired by Cursor: MCP config context variables (${userHome}, ${workspaceFolder}, ...)

* fix(video): read analyze inputs through terminal backend

* fix(video): route terminal-backend reads through the shared media resolver

Follow-up on the salvaged commit: replace the hand-rolled file_ops python3
exec-read with tools.image_source.resolve_image_source(permitted=('video',)),
so video_analyze gets the same pipeline as vision_analyze — media-cache host
reads, bounded head -c sandbox exec (no python3 dependency in the sandbox
image, no unbounded base64 stream), lazy env bring-up (#62825), the
credential-read guard, and the 50MB ingest cap.

* fix(vision): retry container exec-read for Docker cold-start, surface stderr (#76566)

Under the Docker terminal backend, vision_analyze's first exec-read
sometimes returned empty / non-zero against a freshly started container,
producing 'could not read <path> inside the sandbox' on a file the agent
could cat seconds later. Cold pipe setup on the first exec against a
new container, not a permissions or mount problem.

Retry once after a short delay (150 ms covers Docker exec warm-up
without making a real failure feel sluggish). When every attempt still
fails, fold the container's first stderr line into the raised error so
the user can tell 'no such file' from 'permission denied' instead of
staring at one opaque message.

Tests cover the retry-then-succeed path, the diagnostic-on-exhausted
path, and confirm the existing single-attempt raise is preserved.

* feat: --resume latest keyword and --in DIR launch flag

--resume latest resolves the most recent session through the same
workspace-scoped MRU lookup as -c (TUI source first under --tui, with
classic-CLI fallback). --in DIR chdirs before session resolution so the
lookup keys off DIR's workspace, and pins the session there by skipping
the recorded-cwd restore.

Requested by @Jeff9James: hermes --tui --resume latest --in ./dir

* feat(skills): add email-inbox-triage

* chore(skills/email-inbox-triage): tighten to hardline standards

- description 219 -> 58 chars
- author credits Ben Barclay (benbarclay) first
- modern section order; trimmed template safety boilerplate into
  step-local rules and a skill-specific verification checklist
- tests at tests/skills/test_email_inbox_triage_skill.py (9 passing)
- docs regen scoped: per-skill page + one catalog row + one sidebar line

* fix(image_gen): confine generation source images to the terminal backend

image_generate and video_generate forwarded model-supplied local paths to
provider plugins, which read them off the HOST filesystem regardless of
terminal backend — inconsistent with the confinement boundary vision/video
analysis enforce (GHSA-gpxw-6wxv-w3qq), and broken for sandbox-only files.

New dispatch-layer chokepoint (_confine_source_images): under a non-local
backend, path-like image_url / reference_image_urls resolve through
tools.image_source (media-cache host reads, bounded in-sandbox exec-read,
lazy env bring-up, credential guard, 50MB cap) and reach every provider as
data: URLs — which all backends already accept. URLs/data: pass through;
local backend is a no-op. xai_video_edit/extend already require public
HTTPS URLs, so no change needed there.

* fix(security): redact terminal exception results and ACP stderr logs (#77484)

Closes the last two emission gaps from #77484:

- tools/terminal_tool.py: both exception paths (generic except and
  TERMINAL_DEGRADED_MODE=fail) returned raw str(e) + traceback.format_exc()
  to the model — only the logger copy was redacted. Exception text can
  embed the failing command line and any secrets inline in it; both fields
  now pass through redact_sensitive_text.
- acp_adapter/entry.py: _setup_logging cleared root handlers and installed
  a plain logging.Formatter, bypassing redaction entirely on ACP stderr.
  Now uses RedactingFormatter like every other logging surface.

The other three gaps from #77484 (process(list), *_KEY regex variants,
control-char splits) were fixed in #80964/#80965.

* fix(read_file): warn when PDF pages yield no text (scanned-image coverage gap)

anydoc converts the PDF text layer only and emits no image placeholders
or page markers, so a mostly-scanned PDF extracts 'successfully' into
section headers with empty bodies — silent data loss the model cannot
detect. Count per-page text via poppler pdftotext and prepend an
EXTRACTION COVERAGE WARNING naming the empty pages and the recovery
path (pdftoppm + vision_analyze, or the ocr-and-documents skill).

Found on a 311-page HOA resale package where 198 scanned pages
(CC&Rs, Bylaws, Articles, insurance certs) vanished without a trace.

* fix(terminal-tool): redact terminal error result fields

Force-redact every terminal exception and traceback field before JSON serialization, including environment creation, background startup, exhausted foreground retries, and the outer catch-all. Preserve the current command-aware, opt-out-respecting redact_terminal_output(output, command) behavior for successful output.

* Port from superagent-ai/grok-cli: description-aware slash-menu fuzzy scoring

* Port from superagent-ai/grok-cli: directory-chain AGENTS.md loading

* feat: add new FAL video families and image models

Video (plugins/video_gen/fal): Seedance 2.5, MiniMax H3, Seedance 2.0
Mini, FLUX 3, Grok Imagine 1.5, Gemini Omni Flash (i2v-only). New
family capability flags:
- duration_int: endpoints that take duration as a JSON integer
- resolution_aliases: maps 720p/1080p-style values onto non-standard
  enums (H3's 768P/2K/4K)
- image_drop_keys: strips keys the family's i2v endpoint rejects
  (aspect_ratio on Seedance 2.5 / H3 / Grok 1.5)

Image (tools/image_generation_tool): Seedream 5.0 Pro (+edit) and
Lite, Ideogram V4 instant + fast, Qwen Image 3 (+edit), MAI Image 2.5
Pro, Nano Banana 2 Lite (+edit), Recraft V4.1.

Every new endpoint live-tested against fal.run through the real
payload builders + submit path: 18/18 pass (t2v, i2v, t2i, and edit
probes). Note: several new endpoints return HTTP 409 from the Nous
Portal FAL proxy allowlist until it is updated portal-side; BYOK
FAL_KEY works today and the existing 4xx guidance message covers it.

* Inspired by Cursor: fail-closed hook semantics + exit-code-2 blocking

* fix(learn): extend existing skills during relearning

* fix(learn): process large sources incrementally

* fix(tools): preserve document extraction boundaries

* fix(read_extract): keep scanned-PDF coverage warning on the backend bytes path

The salvaged bytes path (_extract_anydoc_bytes) bypassed the coverage
check added in #81680. Materialize transferred PDF bytes in a host temp
file for the pdftotext scan, and name the backend-visible path in the
recovery command rather than the temp file.

* docs: document read_file document extraction and the scanned-PDF coverage warning

* fix: post-merge audit follow-ups for #81138/#81139/#81141/#81148

Four fix-forwards from the adversarial post-merge audit of the Aug 7
unreviewed merge batch:

- estop (#81148): is_engaged() now fails SAFE (engaged) on stat errors;
  the gateway estop gate lets recognized slash commands and replies owned
  by in-flight work (update prompts, clarify, slash-confirm, tool
  approvals, running sessions) through instead of consuming them; new
  gateway /pause [reason|off] command gives messaging-only operators an
  in-band engage/resume path (busy_policy=dispatch so it works mid-run).
- cron monitor mode (#81138): execution-mode invariants (monitor x
  no_agent, monitor_script x monitor_url, no_agent-requires-script) now
  have ONE owner (_validate_job_mode_invariants) called from BOTH
  create_job and update_job, so the create-time invariant can no longer
  be silently violated through the update door.
- cron notepad (#81139): remove_job now clears the job's notepad rows
  (clear_notepad was dead code -> orphaned KV state forever); clear is
  best-effort and no-ops without creating notepad.db.
- delegation batch gate (#81141): template-marker regex narrowed to
  multi-word placeholder shapes only (<feature name>, {file_path}) so
  generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string
  style no longer reject legitimate batches; duplicate-goal rejection
  removed (best-of-N fan-outs are legitimate).

* fix(api-server): mark replayed tool calls completed in Responses output items

The non-streaming /v1/responses path built function_call and
function_call_output output items with no status field (and no item id),
while the SSE streaming path correctly emits status in_progress ->
completed. Spec-strict OpenAI clients reading the non-streaming output
array could interpret the status-less function_call items as pending
calls the CLIENT must execute — but these tools were already executed
server-side by the Hermes agent and are replayed for structured tool UI
only. Reported by a community user whose GPT-5.6 client concluded 'a
server should not tell an OpenAI client to execute a tool the server
already executed itself'.

- _extract_output_items now stamps status: completed and spec-shaped
  item ids (fc_/fco_) on replayed items, matching the streaming path
- test updated to pin status + id shape
- docs example updated + explicit note that output tool calls are
  replayed, never pending

* feat(skills): add github-issue-to-pr

* chore(skills/github-issue-to-pr): de-router, fold in maintainer issue-to-PR discipline

Rewrote from a sibling-skill routing table into a skill that carries its
own procedure, and folded in generalized rules from maintainer practice:

- full-thread reads (gh issue view --comments; newest comment = live state)
- duplicate-PR sweep (issue number + keyword variants) before any code
- design-intent check via git log -p -S alongside premise reproduction
- fix the class: sweep sibling call sites into the same PR
- sabotage run: prove the regression test fails without the fix
- open the PR immediately (PR dispatches CI; CI latency is the long pole)
- close the loop: comment the issue with the PR link

Also: description 205 -> 59 chars, author credits Ben Barclay first,
modern section order, boilerplate trimmed, tests (10) incl. a
router-pattern guard, scoped docs regen.

* feat(image_gen): add FAL Nano Banana 2 model

* test: convert NB2 catalog snapshot test to invariants; live-verified t2i+edit

Follow-up on the cherry-picked contribution from @michaelsam94 (#51794):
replace display-string/exact-value snapshot assertions with invariant
checks per the no-change-detector-tests policy. Live-tested
fal-ai/nano-banana-2 and fal-ai/nano-banana-2/edit through the real
payload builders: both pass.

* fix(read_file): surface document extraction failures instead of the generic binary-file error

When extraction of a binary document format (.pdf, .docx, .xlsx, Office,
EPUB…) fails for a specific reason — the anydoc size cap, an encrypted or
malformed file — read_file previously swallowed the ExtractionError at
debug level and fell through to the generic 'Cannot read binary file'
guard, so the agent never saw the actionable reason (e.g. 'Document too
large to convert (N bytes, limit is 52,428,800)').

read_file now returns the specific extraction failure for binary document
formats. Fallthrough behavior is preserved where a raw read is still
useful: .ipynb (plain JSON) and converter-unavailable PDFs keep their
historical raw-read path, and the 'Unsupported document type' shape (no
extra information) keeps the generic guard.

Follow-up to #80004, where the size-cap message was being generated but
never reached the agent.

* fix(docker): read attached binary files in backend (#76577)

* fix(docker): close the cold-container and multi-backend gaps in attachment delivery

Follow-ups on the salvaged commit:

1. get_cache_directory_mounts() now CREATES missing staging dirs instead of
   skipping them. Docker snapshots the mount list at container creation, so
   a dir born later (first attachment, first clipboard image) dangled for
   the life of a persistent container. Empty bind mount costs nothing.

2. to_agent_visible_cache_path() translates per-backend instead of
   docker-only: docker/modal -> /root/.hermes, ssh/daytona/vercel_sandbox ->
   ~/.hermes (shell-expanded remotely; bytes arrive via file sync), local/
   singularity keep the host path (apptainer auto-binds the host home).
   Mirrors the proven _agent_cache_base_for_env heuristics.

Updated the two mount-list tests pinning the old skip behavior; added
per-backend translation coverage.

* feat(read_extract): label each unreadable PDF gap with its preceding section text

The coverage warning listed bare page ranges, which tells the agent
WHERE the gaps are but not WHAT they contain — its only options were
guessing or OCRing everything. Each gap is now labeled with the last
text extracted before it (usually a section divider page), so the agent
can decide which gaps it actually needs and render/OCR only those.
Gap list capped at 20 entries with a summary line for pathological
alternating documents.

* test(tests): stabilize write_json concurrent serialization flake

* fix(slack): insert resolved display names literally when humanizing mentions

_humanize_user_mentions rewrites <@UID> to @DisplayName by passing the
resolved name as re.sub's replacement, where re parses it as a template.
A display name is arbitrary user-set text, so the escapes in it are the
user's characters, not regex syntax:

  dev\ops  -> re.error: bad escape \o
  a\1b     -> re.error: invalid group reference 1
  \g<0>    -> expands to the whole match, silently putting the opaque
              <@UID> back — the token this method exists to remove

The trigger-text call site sits in _handle_slack_message outside any try,
and both Bolt event handlers await it bare, so the raise takes the whole
inbound message down: every message mentioning that person is dropped.

Pass the replacement as a function instead — re does no template parsing
on the return value, so the name lands verbatim. Same shape the Matrix
adapter already uses for its outbound mention rewrite.

* feat(skills): add google-workspace-daily-brief

* chore(skills/google-workspace): fold daily-brief into references/, not a sibling skill

The brief is single-connector (every command comes from google-workspace),
so it ships as references/daily-brief.md with a pointer + load trigger in
SKILL.md — progressive disclosure instead of a new skill-index entry.
Contributor's procedure preserved (half-open day windows, mail-to-meeting
linking with fuzzy-match discipline, 7-section brief, bounded actions);
credit noted in the reference header. Tests (8) guard the wiring and
disciplines. Version 1.1.0 -> 1.2.0.

* fix(curator): protect cron skills referenced by absolute path

4c2961c51 added referenced_skill_names() so the curator never archives a
skill a cron job depends on — paused jobs and infrequent schedules would
otherwise age their skills out and the next run fails to load them.

62972060c then taught the scheduler that jobs may store ABSOLUTE skill
paths, normalizing them through normalize_skill_lookup_name before
skill_view. The protection set kept returning the raw string, so it now
holds a full path while the curator matches it against bare skill names.
Those jobs silently lost their protection: the skill is archived, and the
next fire logs a warning and runs the job without its instructions.

Canonicalize each reference the same way the scheduler resolves it, with
a deferred import and a verbatim fallback so a resolver failure can never
drop a name (referenced_skill_names has exactly one caller, the curator's
protection lookup, so nothing else sees the change).

* fix(docs): retain prior builds' hashed assets across Pages deploys

Pages serves exactly the newest artifact, so every push-triggered deploy
deleted the previous build's content-hashed JS/CSS while edge caches
(max-age=300, stale-while-revalidate=3600) kept serving HTML that
referenced them. With deploys landing every ~15-30 min, docs pages spent
most of the day pointing at 404'd bundles — search (pure client JS) was
the loudest casualty.

Fix: keep a rolling 14-day pool of hashed assets (en + zh-Hans) in the
Actions cache and union-merge it into each deploy artifact, current
build authoritative on collision (cp --update=none). Stale HTML and
already-open tabs now keep resolving across any number of deploys.

* fmt(js): `npm run fix` on merge (#81849)

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* feat(skills): add meeting-action-items

* chore(skills/meeting-action-items): tighten to hardline standards

- description 178 -> 59 chars
- author credits Ben Barclay (benbarclay) first
- dropped phantom 'Linear' connector from prose (points at notion/
  github-issues/user's tracker instead)
- Hermes-tool framing (read_file for transcripts)
- template boilerplate folded into step-local rules and skill-specific
  verification
- tests at tests/skills/test_meeting_action_items_skill.py (10 passing,
  incl. phantom-connector guard and reconcile-before-create discipline)
- docs regen scoped: per-skill page + one catalog row + one sidebar line

* feat(agent): read_window_below tool — which OS window is underneath the desktop app

Desktop-gated (desktop_ui toolset) metadata-only window awareness: the agent
can ask which application window sits directly behind the Hermes window
(app, title, bounds — never pixels). Rides the same blocking bridge as
read_terminal: the gateway emits window.read.request and the renderer
answers window.read.respond.

* feat(desktop): answer window.read.request with the window below

New electron/window-below.ts: pure z-order picker (walks past our own pid,
first other-process window whose bounds overlap ours) over get-windows'
front-to-back enumeration, with the Linux xprop stacking order reversed to
match (EWMH _NET_CLIENT_LIST_STACKING is bottom-to-top). Main answers the
hermes:window:readBelow IPC; on macOS other apps' titles pass through only
when Screen Recording is already granted — never prompted for.

* build(desktop): stage get-windows like node-pty

get-windows@9.3.0 (MIT, zero runtime deps on macOS/Linux) is external to the
esbuild bundle and staged into dist/node_modules per target platform: the
universal Swift helper on macOS, the prebuilt N-API binding on Windows
(fail-closed magic-byte validation), nothing on Linux (xprop at runtime).
The staged lib/windows.js is rewritten to load the binding directly so
@mapbox/node-pre-gyp's tree stays out of the package.

* test: pin read_window_below into the toolset + post-hook contracts, appease eslint

The desktop_ui and post-hook ownership contract tests enumerate their tool
sets exactly — add read_window_below to both (plus the executor-path
parametrize case). Lint: sorted type import, explicit GetWindowsModule type
instead of an import() annotation, curly + blank-line style.

* fix(build): win32 get-windows staging must skip the tarball's bundled darwin binding

The published tarball ships lib/binding/napi-9-darwin-unknown-arm64 on every
platform, so a real Windows host has both it and the downloaded win32 binding
— the classify-everything gate threw on the darwin dir and killed every
Windows pack. Stage only bindings naming the target platform (classify still
rejects impostors), stop copyGlobByExt from recursing into lib/binding, and
add a version tripwire so a get-windows bump fails the build until the
lib/windows.js rewrite is re-verified.

Also from review: the renderer answers window.read.respond with empty text
when the IPC invoke rejects (older shell / main-side throw) instead of
stalling the tool's 30s timeout; the tool schema discloses that sibling
Hermes windows are skipped; docs gain read_window_below in both references.

* fix(tts): split long speech by provider and platform limits

Salvage of PR #17973 by @TKCen (Sebastian Hänisch), re-implemented on
current main to preserve speed/instructions/provider params,
prepare_spoken_text normalization, OPUS_VOICE_PLATFORMS, is_write_denied
path security, microsecond timestamps, and the streaming-TTS gate.

- Split long TTS text into provider-safe chunks instead of truncating
- Pack generated audio against platform upload limits (Discord 10MB,
  Telegram 50MB, configurable via tts.delivery_profiles)
- Combine chunks with ffmpeg (OGG/Opus re-encoded, MP3 stream-copied)
- Multi-file delivery when combination fails or would exceed limits
- Remove hard [:4000] truncation from all callers (cli.py, voice.py,
  gateway/run.py, gateway/platforms/base.py)
- Gemini TTS raises ValueError instead of silently truncating when
  composed prompt exceeds the provider limit

Simplify-code fixes: removed dead all_touched_paths set, added
try/finally for scratch file cleanup on exception, clean error response
on chunk failure instead of leaking stale file_path.

* fix(desktop): an empty HUD thread shouldn't paint a blank panel

A fresh thread has nothing to show, but the HUD showed a slab of frosted
glass above the bar anyway. Vibrancy is the window's whole content view, so
it frosts the full rectangle — fine while the band always filled the window,
wrong the moment there is no transcript to fill it. It stays off until there
is something to back.

The sheet had a 12px floor for the same reason: the breathing room above the
first row was added in CSS, so a zero-row transcript still measured 12. It is
folded into the measured height now and only applies when there are rows.

* fix(gateway): support Docker /workspace media paths in gateway delivery

Translate MEDIA paths under configured Docker volume mounts (and the
default persistent /workspace) to host paths before media delivery
validation, using longest container-prefix match so host:/workspace and
/output export mounts work.

* fix(gateway): widen container->host media translation to home, cache, and in-process gateways

Follow-ups on the salvaged commit (#37207 by @charzhou):

- Persistent /root home mount translates too: an agent writing
  /root/out.png produced a real host file under
  <sandbox>/docker/default/home the gateway could not find.
- /root/.hermes cache mounts translate to the HOST cache (longest-prefix
  beats the home mount), so MEDIA:<agent_visible_image> paths deliver.
- /root/.hermes/* OUTSIDE a cache mount never translates through the home
  mount: those are the sandbox's credential copies (.env, auth.json) that
  sit outside the host-side denylist prefixes — fail closed.
- Run the idempotent terminal-config->env bridge before mount parsing so
  in-process gateways (Desktop backend, hermes serve) see the active
  backend and docker_volumes (covers #42299's /output case there too).

* feat: add DCP context engine

Cherry-picked from PR #20774 by @jmmaloney4 (jmmaloney4@gmail.com).
Original commits: 4420e0b0, 44247545, bac2955d.

DCP-style model-guided context engine behind context.engine: dcp.
Adds compress tool, outbound API-call transforms, automatic dedup/purge,
and DCP-compatible config surface.

Closes #20717
Co-Authored-By: Jack Maloney <jmmaloney4@gmail.com>

* fix: rewire DCP context engine to current main architecture

Fixes 13 issues found in PR #20774 review:

1. Wiring: engine selection moved from run_agent.py to agent/agent_init.py
   (where init_agent lives on current main). Transform hook moved from
   run_agent.py to agent/conversation_loop.py (where run_conversation lives).

2. Prompt caching: replace copy.deepcopy with copy-on-write (shallow list
   copy + clone only messages that are mutated). Use last_prompt_tokens
   from update_from_response instead of re-estimating tokens every call.
   System extension injection is idempotent (one-time cache break).

3. Signature mismatch: _message_signature renamed to _content_signature
   and now excludes tool_calls/tool_call_id from the hash. This prevents
   mismatches when _canonicalize_api_tool_calls re-serializes argument
   JSON with sort_keys=True on the API copy.

4. update_model: accepts api_mode parameter (required by agent_init.py).

5. Reconciled with select_context: transform_api_messages is a separate
   hook that runs AFTER select_context and sanitization, before
   prompt-cache marker placement. Both hooks coexist with clear ordering.

6. Dedup/purge: kept as DCP-specific strategies (different semantics from
   ContextCompressor._prune_old_tool_results — DCP deduplicates by
   tool+args signature, not by content hash).

7. Removed copy.deepcopy: replaced with shallow list copy + copy-on-write
   via _clone_if_needed. Only messages that are actually mutated get
   cloned.

8. Removed redundant _ensure_refs call: _match_api_messages_to_refs no
   longer calls _ensure_refs (the caller already called it).

9. _message_key still uses index (needed for positional ref assignment),
   but _content_signature is cached per id(msg) to avoid re-hashing.

10. _inject_nudge: only injects into user messages, never falls back to
    non-user messages (prevents role semantics violations).

11. Memory: _evict_inactive_blocks bounds blocks_by_id to
    _MAX_INACTIVE_BLOCKS (50) deactivated blocks.

12. Merged _range_tool_schema and _message_tool_schema into a single
    _compress_tool_schema. Merged _handle_range_compress and
    _handle_message_compress into _handle_compress.

13. Dropped DCP_CONTEXT_ENGINE_PR_SPEC.md (temporary file, not for tree).

Config defaults kept minimal in hermes_cli/config_defaults.py (only
the keys the engine actually reads, not the full DCP-compatible surface).

Closes #20717

* Revert "feat: add DCP context engine"

This reverts commit d7072ab914de0bd3c98cd5cf006fd193a5ee752d.

* Revert "fix: rewire DCP context engine to current main architecture"

This reverts commit 9841a6c65161b9253c342f04b20f3a8bdb63884c.

* fix: clean up SkillEvaluator Tier 1 security findings in bundled skills

Findings from scanning skills/ + optional-skills/ with NVIDIA
SkillEvaluator's deterministic Tier 1 checks (PII/secrets, unicode
smuggling, script lint):

- pixel-art, pokemon-player: remove hardcoded /home/teknium/ personal
  paths (use ~ / portable phrasing); pokemon-player no longer claims
  machine-specific state as fact
- kanban-video-orchestrator: replace <path> angle-bracket token in
  frontmatter credits (flagged as XML-in-frontmatter prompt injection)
- comfyui, hermes-agent, unsloth, 1password, actual-setup: rephrase
  placeholder secrets so they no longer pattern-match real credentials
  (your-* placeholder convention, comment markers, {env:...} form)
- docker-management, pytorch-lightning: drop user:pass@ from example
  connection strings (env/secret-manager guidance instead)
- evm: break up Keccak round constant that Luhn-validates as a credit
  card number (digit-group underscores, value unchanged)

All targeted skills now pass pii+unicode+lint 3/3 except unsloth, which
retains scanner false positives only (Colab notebook IDs read as Bitcoin
addresses; an email inside a quoted upstream system prompt).

* feat: replace Anthropic office document skills with clean-room MIT implementations

The bundled docx, xlsx, powerpoint, and pdf skills were adapted from
Anthropic's document skills and carried their proprietary LICENSE.txt
(no derivatives, no redistribution). Flagged as critical license
findings by the SkillEvaluator Tier 1 scan of our skill tree.

This replaces all four with clean-room rewrites:

- Authored from scratch against library knowledge only (python-docx,
  openpyxl, python-pptx, pypdf/reportlab/pdfplumber — all MIT/BSD) by
  isolated subagents given functional specs, with an explicit
  prohibition on reading the prior skill content or anthropics/skills;
  session transcripts retained as provenance evidence.
- MIT licensed (LICENSE file per skill), author: Nous Research.
- Each skill: SKILL.md to house standards + argparse helper scripts
  with UTF-8-explicit I/O + its own e2e pytest suite (fixtures built
  on the fly, non-ASCII round-trips run under LC_ALL=C).
- All four pass SkillEvaluator Tier 1 pii+unicode+lint 3/3.

tests/skills/test_office_document_skills.py rewritten against the new
contracts: MIT/no-Anthropic-text invariants, scripts documented in
SKILL.md, argparse CLI shape, and a no-locale-default-open() check
(which caught and fixed a real gap: pdfplumber text reads are fine,
but the invariant scan now guards every future script).

Docs pages regenerated for the four skills (scoped; unrelated
generator drift excluded).

Honest capability deltas vs the old versions are documented per
SKILL.md (e.g. tracked-changes accept/reject and OOXML XSD validation
are not reimplemented; form flattening limits stated).

* feat: extend clean-room office skills toward full parity

Same clean-room discipline as the initial rewrite (isolated subagents,
functional specs only, predecessor content banned including via git
history; transcripts retained). All additions test-proven.

docx (13->29 tests):
- docx_revisions.py: tracked changes list/accept/reject (all or by id),
  incl. tables and headers/footers, via direct oxml manipulation
- docx_comments.py: list/add/delete comments (native python-docx >=1.2
  API with XML fallback), anchored-text extraction
- docx_validate.py: package health check (rels, images, styles, CRC)
  with JSON severity report — explicitly not XSD validation
- docx_edit.py: run normalization; TOC + PAGE/NUMPAGES field insertion

xlsx (5->12 tests):
- xlsx_restructure.py: reference-aware insert/delete rows/cols —
  rewrites formulas on all sheets (absolute refs, ranges, cross-sheet,
  quoted names), shifts merges/autofilter/freeze/validation/CF ranges,
  tables, defined names; JSON report incl. honest not_shifted list
- native Excel tables, named ranges, hyperlinks, cell notes,
  sheet protection (documented as strippable, not security)
- xlsx_recalc.py: headless LibreOffice recalc with graceful degrade

powerpoint (11->21 tests):
- pptx_render.py: all slides -> PNGs (soffice + pdftoppm/pdftocairo),
  wired to vision_analyze review loop in SKILL.md
- run-merge normalize before replace (identical-format splits lossless)
- surgical chart ops (series/category/title) wrapping replace_data
- slide duplication with rel remap (clean refusal on chart slides)
- backgrounds, hyperlinks, slide numbers, footers, notes editing

pdf (8->21 tests):
- pdf_make_form.py: JSON spec -> AcroForm (text/checkbox/radio/dropdown)
- pdf_form_layout.py: pre-build layout lint (bounds/overlap/pairing)
  + rendered box overlay for vision_analyze review
- pdf_page_image.py + shared _raster.py: pypdfium2 -> pdftoppm chain,
  graceful degrade; connected to scanned-PDF triage flow
- pdf_stamp.py: text/image stamps at coordinates (rotation/opacity)
- pdf_meta.py: DocInfo metadata + attachments round-trip

Gates re-verified independently: 83 skill tests green under LC_ALL=C,
repo invariant suite 29/29, SkillEvaluator pii+unicode+lint 3/3 x4.

* fix(desktop): don't frost the HUD window the sheet isn't covering

The frost is native vibrancy, which is the window's content view rather than
an element — it fills the whole rectangle and nothing in the page can clip it
to the sheet. That was only ever right while the sheet covered the window;
anywhere it falls short, the difference is frost over empty space. On a fresh
thread the sheet is zero and the difference is the entire window, which is the
grey slab that appears the moment you put the caret in the composer.

Gating the caller's `engaged` was not enough, and is why the first attempt at
this missed: the hook turns the frost on for a focused composer by itself,
independent of what the caller passes. The veto belongs inside, next to that
check.

* fmt(js): `npm run fix` on merge (#81914)

Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>

* feat(skills): advisory SKILL.md convention linter on create

Adds tools/skill_linter.py — a soft companion to the hard frontmatter
validator. It encodes the CONTRIBUTING 'Skill authoring standards
(HARDLINE)' conventions that today only a human reviewer catches:

- shell-utility references in prose (`grep`/`sed`/`cat`...) that should
  name the native tool (search_files/patch/read_file)
- missing version/author/license/metadata.hermes block
- name != directory, invalid name format
- description over the 60-char prompt budget, marketing words
- dangling references/ links, forbidden scaffolding files
- POSIX-only script primitives without a platforms: gate

Findings are ADVISORY. skill_manage(create) attaches them as
lint_warnings + lint_hint in the success result; nothing is blocked
(the hard rejects already run in _validate_frontmatter). A CLI
(python -m tools.skill_linter <dir>) exits 1 only on ERROR-severity
findings so CI can gate on structural breakage without failing on nits.

Calibrated against the bundled skills/ tree: 76 advisory findings, exit 0,
no false positives after excluding repo-root scripts/ refs.

Inspired by MiniMax Code's skill-creator lint step; adapted to our
existing validator + skill_utils rather than a parallel system.

* fix: suppress windows-footgun false positives in linter pattern list

The _POSIX_PRIMITIVES tuple holds search-pattern STRINGS the linter
greps for in skill scripts — 'os.setsid' / 'signal.SIGKILL' are data,
not calls. Add inline # windows-footgun: ok suppressions.

* fix(api-server): resolve reasoning for the request's model, not model.default

e81d18dfb collapsed six per-surface copies of reasoning resolution onto
resolve_reasoning_config() and, in its own words, "fixes the gateway
resolving reasoning against config model.default instead of the session's
effective model". It did not touch gateway/platforms/api_server.py, which
kept that defect.

_create_agent() called GatewayRunner._load_reasoning_config() with no
model on its first line — before the model precedence chain (browser lock
-> session /model -> session row -> route -> per-request -> defaults) has
run. Per-model agent.reasoning_overrides therefore keyed off model.default
on the one surface where every request names its own model: a request for
a model with an override silently got the global effort instead.

Resolve after the chain settles, so the override follows the model the
request actually runs. An explicit per-request reasoning parameter still
takes precedence over config.

The existing test stub for _load_reasoning_config took no arguments (it
mirrored the old call); it now matches the real signature, as the sibling
stub in the same file already did.

* feat(docs): replace local lunr search with Algolia DocSearch

The local-search plugin shipped a ~16 MB client-side lunr index that
every visitor downloaded and hydrated before their first result — slow
on any connection, painful on poor ones, and another lazy-loaded chunk
that died during deploy skew windows. DocSearch answers from Algolia's
servers: no client index, instant results at any docs size.

- themeConfig.algolia with public search-only credentials (admin key is
  not in the repo); contextualSearch keeps en/zh-Hans results separated
  via the crawler's docusaurus_tag facets
- drop @easyops-cn/docusaurus-search-local from package.json + lockfile
- index live and verified: 9,404 records, query 'telegram' returns 374
  hits with correct URLs

* feat(skills): add product-price-monitor

* chore(skills/product-price-monitor): cron-recipe shape + price-watch blueprint

Skill polish (hardline standards):
- description 199 -> 58 chars; author credits Ben Barclay (benbarclay) first
- moved research/ -> productivity/ (consumer task, not research)
- restructured into Setup (foreground, once) / Tick (each scheduled run)
  phases with explicit cronjob(action='create') wiring and a state file
  at ~/.hermes/price-watches/
- dropped phantom 'flight-research' related_skills/prose refs
- Hermes-tool framing (web_extract, browser_navigate)

Blueprint half:
- new 'price-watch' Automation Blueprint (item/condition/interval_h/
  deliver slots) loading the skill via skills=(...), [SILENT] no-alert
  path, catalog now 15 blueprints; blueprints index regenerated

Tests: 12 skill tests incl. setup/tick split, state discipline, blueprint
registration + schedule resolution; existing blueprint catalog suite green
(33 total across both files).

* fix(skills): pin text-mode file I/O to UTF-8 in comfyui and pdf skill scripts

The bundled comfyui and pdf skills read and write text files with the
locale-default codec. Both declare platforms: [linux, macos, windows], so
these paths run on hosts where that codec is not UTF-8 (cp1252 on US
Windows, cp936 on Chinese Windows, ASCII under LC_ALL=C).

Readers (the live bugs):

- run_workflow.py load_schema() and the main() workflow read parse
  user-authored JSON. A non-ASCII label crashes json.load with
  UnicodeDecodeError under a non-UTF-8 locale, and a file saved from a
  Windows GUI editor carries a UTF-8 BOM that json.load rejects with
  JSONDecodeError. Both are read as utf-8-sig, which is BOM-tolerant and
  identical to utf-8 on BOM-less input. This differs from adecb0d1a,
  which used plain utf-8 for the pdf form JSON; those payloads are
  agent-authored and BOM-free by construction, these are not.
- hardware_check.py reads /proc/version and /proc/meminfo. Both are
  Linux-gated so Windows never reaches them, but the C locale defaults to
  ASCII, so they pin plain utf-8. No BOM is possible on /proc.

Writers (not currently broken):

- extract_form_structure.py and extract_form_field_info.py write their
  JSON with json.dump, whose default ensure_ascii=True keeps the bytes
  pure ASCII. Pinned anyway because the codec is the writer's contract,
  not a property of what the caller happens to dump.

wf_path.open() is a Path.open() site that check-windows-footguns.py
deliberately does not flag (per the rule comment: "Path.open() is ALSO
affected ... and can be audited separately"). It is fixed here because it
is the same bug 156 lines from a site the checker does flag, and line 623
of the same file already uses read_text(encoding="utf-8").

Adds tests/skills/test_comfyui_skill.py with contract assertions plus two
live regressions that run load_schema in a child interpreter under
LC_ALL=C with PYTHONUTF8=0, and extends the office skill tests with writer
contract assertions. All 8 new tests fail without this change.

Note that pyproject.toml exempts skills/** from ruff PLW1514
(unspecified-encoding) because skill scripts are partly user-authored.
This change does not touch that exemption; the sites are fixed by hand,
the same way adecb0d1a did.

* fix(skills): widen BOM-tolerant reads to all comfyui workflow-JSON call paths

The salvaged fix covered run_workflow.py and hardware_check.py. The same
locale-default read of user-authored workflow JSON exists in five sibling
scripts (auto_fix_deps, check_deps, extract_schema, health_check,
run_batch) — same bug class, same utf-8-sig fix. Invariant test extended
to pin all nine read sites.

The pdf half of the original PR is superseded: those scripts were
replaced wholesale by the clean-room rewrite (#81890), which ships
UTF-8-explicit I/O enforced by its own invariant test.

* feat(compression): native OpenAI Responses server-side compaction for gpt-5.6

Opt-in via compression.codex_responses_native (default: false). When enabled,
gpt-5.6-family models on the direct OpenAI API (api.openai.com) or a ChatGPT
Codex subscription send context_management=[{type: compaction,
compact_threshold: N}] on Responses requests. OpenAI compacts server-side and
returns an encrypted compaction output item; Hermes captures it into the
existing codex_reasoning_items sidecar and replays it on later turns in place
of the pruned history — inheriting persistence, session replay, the
cross-issuer guard, and the encrypted-replay kill switch with zero new state.

Scope is deliberately hard-gated (agent/native_compaction.py, re-checked per
request): gpt-5.6 family only — gpt-5.1/5.2 fail server-side on the field
(HTTP 500 / stream stall, no structured rejection; live-verified) — and
direct OpenAI/Codex routes only; xAI, GitHub/Copilot, OpenRouter, relays,
and local servers never see the field.

Hermes' local compression stays armed as the fallback owner: the native
threshold is clamped ~8K tokens below the local trigger so the server
compacts first, and a structured provider rejection of context_management
disables native compaction for the session and retries without it
(one-shot guard in TurnRetryState).

Live-verified E2E on api.openai.com/gpt-5.6: server compaction fired at a
4K threshold, checkpoints captured and replayed, recall preserved across
3 turns; gpt-5.1 with the flag enabled stays clean (field never sent).

Direction credit: PR #76950 by @laryhorb explored native Responses
compaction; this is a minimal reimplementation on current main.

* feat(skills): add weekly-review-planning

* chore(skills/weekly-review-planning): hardline polish + wire task blueprints to their skills

Skill polish:
- description 208 -> 57 chars; author credits Ben Barclay (benbarclay) first
- connector framing (google-workspace, obsidian, notion, email-inbox-triage)
- modern section order; boilerplate folded into step-local rules

Blueprint wiring (completes the batch's recipe integration):
- weekly-review blueprint loads weekly-review-planning; prompt follows the
  skill's seven-section shape, drafts-only
- morning-brief blueprint loads google-workspace; prompt points at
  references/daily-brief.md when connected
- important-mail blueprint loads email-inbox-triage
- blueprints index regenerated

Tests: 13 skill tests + two catalog invariants (every blueprint skills=
entry resolves to a real bundled skill; the four task blueprints are wired
to their procedure skills). 32 green across both files.

* feat(config): resolve ephemeral prompt from display.personality

Keep agent.system_prompt user-owned; named personalities resolve as an
ephemeral overlay via display.personality.

Co-authored-by: kyssta-exe <kyssta-exe@users.noreply.github.com>
Co-authored-by: EMT5320 <1908937833@qq.com>

* fix(personality): stop writing personality into agent.system_prompt

Persist display.personality only; apply rendered text as an in-session
overlay across CLI, TUI config.set, and gateway /personality.

Co-authored-by: kyssta-exe <kyssta-exe@users.noreply.github.com>
Co-authored-by: EMT5320 <1908937833@qq.com>

* test(personality): regression coverage for #81791

Assert config.set and /personality preserve manual agent.system_prompt,
and that startup resolution prefers display.personality.

Co-authored-by: kyssta-exe <kyssta-exe@users.noreply.github.com>
Co-authored-by: EMT5320 <1908937833@qq.com>

* feat(skills): add social-media-content-calendar

* chore(skills/social-media-content-calendar): tighten to hardline standards, ship optional

- description 210 -> 57 chars; author credits Ben Barclay (benbarclay) first
- optional-skills/creative/ (marketing vertical, narrowest audience of
  the batch)
- dropped phantom 'image-generation-workflow' ref; visuals via the
  image_generate tool
- honest handoff language: platforms without connectors end at approved
  drafts marked handed-off, never claimed as published
- tests (10) incl. phantom-ref and honest-handoff guards
- docs regen scoped: per-skill page + one catalog row + one sidebar line

* fix: ensure utf-8 encoding in jobs.json

* fix(gateway): write cron delivery output files as UTF-8

Cron and agent output that contains emoji, CJK, or accented text is
silently lost on Windows. When a job's output exceeds the platform limit
(MAX_PLATFORM_OUTPUT = 4000), DeliveryRouter._deliver_to_platform saves
the full text to disk and sends a truncated preview with a "full output
saved to ..." pointer. That save used Path.write_text(content) with no
encoding, so on Windows it encodes through the platform code page
(cp1252) and raises UnicodeEncodeError on any non-ASCII character. The
exception propagates out of _deliver_to_platform and deliver() records
the target as failed, so the whole truncate-and-send path aborts: the
user receives nothing — even though an ASCII payload of the same size
would deliver fine — and the promised backup file is never written. The
sibling local-file path (_deliver_local) had the identical defect. The
Windows-footgun CI gate misses this because it only inspects open() /
Path.open(), not Path.write_text().

Both writes now pass encoding="utf-8" explicitly so output is persisted
consistently across platforms.

Fixes silent loss of non-ASCII cron/agent output on Windows. The two
on-disk writes in the delivery router (`_deliver_to_platform`'s full
output save and `_deliver_local`'s file save) now write UTF-8 instead of
the platform-default code page, so emoji/CJK/accented output is saved
and delivered the same on Windows as on macOS/Linux.

N/A

- [x] 🐛 Bug fix (non-breaking change that fixes an issue)

- `gateway/delivery.py`: pass `encoding="utf-8"` to the `write_text`
  call in `_save_full_output` (oversized-output backup) and the one in
  `_deliver_local` (local file delivery).
- `tests/gateway/test_delivery.py`: add two regression tests that
  simulate a non-UTF-8 Windows code page and assert oversized non-ASCII
  output is still delivered and the backup/local files round-trip as
  UTF-8.

1. `scripts/run_tests.sh tests/gateway/test_delivery.py` — 25 passing.
2. Revert either `encoding="utf-8"` argument and re-run: the two new
   tests fail with `UnicodeEncodeError` from the cp1252 codec, proving
   they catch the regression.
3. `python scripts/check-windows-footguns.py gateway/delivery.py` and
   `ruff check gateway/delivery.py tests/gateway/test_delivery.py` both
   pass.

- [x] I've read the Contributing Guide
- [x] My commit messages follow Conventional Commits
- [x] I searched for existing PRs to make sure this isn't a duplicate
- [x] My PR contains only changes related to this fix
- [x] I've run the gateway delivery tests and all tests pass
- [x] I've added tests for my changes
- [x] I've tested on my platform: macOS 15 (Darwin 25.5)

- [x] I've updated relevant documentation (README, docs/, docstrings) — or N/A
- [x] I've updated cli-config.yaml.example if I added/changed config keys — or N/A
- [x] I've updated CONTRIBUTING.md or AGENTS.md if I changed architecture or workflows — or N/A
- [x] I've considered cross-platform impact (Windows, macOS) — this fix is specifically about Windows code-page encoding
- [x] I've updated tool descriptions/schemas if I changed tool behavior — or N/A

* test(cron): regression coverage for Windows encoding cluster

- CJK/emoji round-trip + human-readable jobs.json (PRs #52302/#29754)
- emoji through no_agent script stdout capture (issue #42384)
- truncated/invalid UTF-8 script stdout must not raise (#47393)

* chore: contributor mapping for zcj1122-rgb

* fix: restore corrupted warning emoji in batch_runner checkpoint handler

* fix(batch): normalize checkpoint warning emoji spacing (salvage follow-up for #32982/#66680)

* fix(telegram): honor UTF-16 entity offsets

* fix(gateway): tolerate invalid UTF-8 update output

(cherry picked from commit 1dee620462c43daacd88783f446c32c6354f5b02)
(cherry picked from commit 295f32dad9b6ad9c3cc61bc0f0e4941ee0ba7617)

* fix(update): handle UnicodeDecodeError in interactive update prompts

Ports #68497 forward onto current main per teknium1's review.

input() can raise UnicodeDecodeError when the terminal encoding
cannot decode the byte sequence (e.g. a non-UTF-8 locale, or an
embedded terminal). The prior port targeted hermes_cli/main.py, the
pre-refactor location -- the update pipeline moved to
hermes_cli/update_cmd.py in 927463efcc.

Per review, fixed all three interactive update prompts that call
input() directly, not just the one this originally targeted:

1. Config-migration prompt (update_cmd.py:~3989): extends the existing
   except EOFError to also catch UnicodeDecodeError, prints an
   actionable 'hermes config migrate' hint, and falls through to the
   skip branch (response=n).
2. Stash-restore prompt (_restore_stashed_changes, ~line 971): the raw
   input() call here had NO exception guard at all -- not even for
   EOFError. Added a try/except covering both EOFError and
   UnicodeDecodeError, falling back to the existing skip-restore path
   (changes remain safely in git stash, restorable manually).
3. Upstream-remote prompt (_sync_with_upstream_if_needed, ~line 1274):
   already caught (EOFError, KeyboardInterrupt) but not
   UnicodeDecodeError -- added it to the existing tuple.

Also dropped the incorrect #12884 reference (a TUI sticky-scroll
report, unrelated to this update-encoding issue, per the review).

4 new tests pass covering all three call sites (config-migration prompt
via cmd_update end to end, stash-restore and upstream-remote prompts
via direct unit tests against their own functions), plus an EOFError
sanity test confirming the stash-restore fix doesn't regress that case
either (it had no guard before). 6/6 in the full
tests/hermes_cli/test_update_yes_flag.py file (no regression).

* test(update): strengthen UnicodeDecodeError regression to assert_not_called()

Follow-up per review of #74631.

The prior assertion (call_count == 0 OR interactive != True) also
passed if an unintended non-interactive migration occurred, which the
safe fallback (response='n') is supposed to prevent entirely. Replaced
with mock_migrate.assert_not_called().

6/6 pass in the full tests/hermes_cli/test_update_yes_flag.py file.

* fix(email): never let unknown or malformed charsets abort the IMAP fetch

Unknown charset labels (QQ Mail's RFC 1428 'unknown-8bit' placeholder,
misspelled names, garbage encoded-word charsets) raised LookupError from
bytes.decode — errors='replace' only guards decode errors, not a missing
codec — aborting the whole fetch batch. UIDs are marked seen before the
fetch, so the crash permanently dropped every message in the batch.

- _safe_decode(): alias table (unknown-8bit→utf-8, gb2312/gbk→gb18030,
  ks_c_5601-1987→cp949, ...) then utf-8, then latin-1 last resort.
- _decode_header_value(): wraps decode_header() so a malformed RFC 2047
  header degrades to the raw string instead of crashing.
- _extract_text_body(): all three decode sites now use _safe_decode.

Fixes #35901, fixes #55381, fixes #55383.

* test(gateway): regression tests for UTF-16 chunk limits at the Telegram boundary (#55844)

* chore: contributor email mapping for salvaged commits

* fix(environments): surrogateescape-safe stdin piping, always close stdin (#79178)

* fix(environments): surface stdin write failures as stdin_error (#79178)

* fix(file_operations): reject unencodable surrogates early, hash with surrogateescape (#79178)

* test(file_operations): pin early surrogate rejection over the backstop (#79178)

* fix(process_registry): surrogateescape-safe PTY stdin writes (#79178)

* fix(cli): scrub lone surrogates before oneshot stdout write

Prevent UnicodeEncodeError when model text contains U+D800-range
surrogates by sanitizing to U+FFFD before writing to UTF-8 stdout.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix(agent,gateway): class-level lone-surrogate chokepoints (#80366 #55143 #55309 #50959 #19819)

Own the surrogate-crash class at three chokepoints instead of leaf sites:

- finalize_turn scrubs final_response once where model text leaves the
  conversation loop — covers oneshot stdout (#80366), NIM/any-provider
  responses (#19819), and every delivery consumer of the turn result.
- _sanitize_gateway_final_response scrubs at the gateway chat-surface
  boundary — Telegram utf16_len (#55309) and Signal formatting (#55143)
  can no longer see a lone surrogate; raw-text surfaces keep passthrough.
- run_conversation walks the fully-built api_kwargs with
  _sanitize_structure_surrogates so tool descriptions (session_search,
  #50959) and every other request-body leaf are JSON-encodable before
  any provider sees them.

Regression tests pin all three chokepoints plus helper semantics.
Cherry-picked alongside #79240 (TheophilusChinomona) and #80374
(rainbowgore) whose commits precede this one with authorship preserved.

* fix(cli): read .env as utf-8-sig so a BOM doesn't drop the first key

PowerShell 5.1 Set-Content -Encoding UTF8 and Windows Notepad write a
UTF-8 BOM. load_dotenv(encoding="utf-8") kept U+FEFF on the first key
name, so the canonical name was absent from os.environ and Hermes looked
unconfigured with no error. utf-8-sig strips the BOM and is a no-op for
BOM-less UTF-8; latin-1 fallback unchanged.

* fix(cli): strip UTF-8 BOM on latin-1 .env fallback path

utf-8-sig only covers the primary decode. BOM + invalid UTF-8 (e.g.
PowerShell BOM + cp1252 body) forced latin-1, which kept EF BB BF as
part of the first key name and dropped the canonical name. Strip the
BOM before latin-1 decode and load via stream so override= is preserved.

* fix(cli): apply BOM-safe .env decoding to hermes send's private loader

send_cmd._load_hermes_env intentionally reimplements a minimal dotenv
load (no secret-source pulls, no sanitize rewrite, get_hermes_home path
resolution incl. Windows/profile override), so the shared-loader BOM fix
is mirrored in place: utf-8-sig primary read, BOM strip before the
latin-1 stream fallback.

Claude-Session: https://claude.ai/code/session_01JPmJz5u1Bvtw4cCRvRWnYr

* fix(auth): read auth stores as UTF-8 to prevent credential loss on Windows

The auth store readers (_load_auth_store, _import_codex_cli_tokens, and the
shared Nous store reader) called Path.read_text() with no encoding, so bytes
were decoded with locale.getpreferredencoding() — cp1252 on Windows. The
stores are *written* as UTF-8 (os.fdopen(..., encoding="utf-8")), so any
non-ASCII byte (a CJK or emoji credential label, an accented display name in
OAuth state) raised UnicodeDecodeError on read.

Worst case: _load_auth_store's broad except then copied the file to .corrupt
and returned an empty store, silently wiping every provider credential on the
next launch. The sibling reader at line 2161 already used
read_text(encoding="utf-8"), confirming the omission was unintentional.

Use utf-8-sig (matching the .env handling in config.py) so a BOM from a
Notepad-edited file is tolerated too.

Adds regression tests covering the UTF-8 round-trip with a non-ASCII label,
BOM tolerance, no-corrupt-on-valid-load, and that the readers pass an explicit
encoding (guard against future regressions). Verified the tests fail when the
fix is reverted.

Closes no issue — found via cross-platform code audit (the bug is not in the
issue tracker).

* fix(auth): cover remaining auth.json readers across modules

Follow-up to the auth.json UTF-8 read fix in this PR. A repo-wide scan for
the same bug class found three more callers that read ~/.hermes/auth.json
via Path.read_text() with no encoding — same Windows cp1252 hazard:

- agent/auxiliary_client.py _read_nous_auth: a non-ASCII byte raised
  UnicodeDecodeError, the broad except swallowed it, and Nous silently
  stopped being available as the auxiliary (vision/summarization) provider.
- tools/xai_http.py has_xai_credentials: same failure mode — xAI OAuth
  silently looked absent on Windows.
- hermes_cli/main.py is_setup_complete: same; has a config.yaml fallback so
  the impact is milder, but the read is still wrong.

All three now use read_text(encoding="utf-8-sig"), matching _save_auth_store's
write encoding. A repo-wide grep confirms there are no remaining
json.loads(...read_text()) reads of auth.json without an explicit encoding.

Tests: rewrote the Windows-encoding regression tests to actually exercise the
bug on POSIX too — a new windows_default_encoding fixture forces a no-encoding
read_text() to decode as cp1252 (the Windows default), and _write_utf8 now
emits real non-ASCII UTF-8 bytes (ensure_ascii=False) so the bytes actually
trip cp1252. Verified each test fails when its fix is reverted (including
the two new sibling-reader tests).

* test(auth): cover the two remaining Windows-encoding readers

Address review feedback on #58158: the regression suite covered four of
the changed readers but not _read_shared_nous_state (auth.py) or
_has_any_provider_configured (main.py), which also read UTF-8 stores the
Windows cp1252 default can corrupt.

Add a non-ASCII UTF-8 regression case for each, reusing the existing
windows_default_encoding fixture and _write_utf8 helper:

- _read_shared_nous_state: a nous_auth.json with an accented display_name
  and valid tokens must round-trip intact (not return None). Pins
  HERMES_SHARED_AUTH_DIR to tmp to satisfy the shared-store seat belt.
- _has_any_provider_configured: an auth.json whose active provider carries
  a CJK label must still report a configured provider (the read must not
  raise into the swallowing except). get_auth_status is faked so the
  result is driven by the read, and provider env vars are cleared to reach
  the auth.json branch.

Both tests are RED-verified — they fail when the respective
read_text(encoding=...) is reverted.

* fix(gateway): read auth.json as UTF-8 in _read_nous_provider_state

tools/managed_tool_gateway._read_nous_provider_state read auth.json with a
bare read_text(), which on Windows decodes as cp1252 and raises on any
non-ASCII byte (e.g. an accented Nous provider label). The broad except
swallowed it and returned None, so the gateway treated Nous as
unconfigured — the same Windows UTF-8 hazard the other auth.json readers
in this PR already fix.

Add encoding="utf-8-sig" (consistent with the sibling readers) plus a
non-ASCII regression test reusing the windows_default_encoding fixture.

This covers the one auth.json reader in #66782 not already handled here
(tools/managed_tool_gateway.py:40); the other two readers #66782 touches
(agent/auxiliary_client.py, tools/xai_http.py) are already fixed in this
PR. RED-verified.

* fix(tools): make json_parse tolerate UTF-8 BOM (salvage #57870)

json_parse used json.loads(strict=False), which relaxes control
characters but rejects a leading UTF-8 BOM (U+FEFF). Windows CLI
tools and some files prepend a BOM, causing JSONDecodeError on
otherwise valid JSON output.

Strip a leading BOM before calling json.loads when the input is
a string with a U+FEFF prefix.

Original PR by @woxinwuhen713-bit (#57870).

Co-Authored-By: Claude <noreply@anthropic.com>

* test(tools): cover UTF-8 BOM input in json_parse sandbox helper

Review asked for a BOM-prefixed JSON case alongside the existing
control-character coverage. The sandbox script now also feeds
json_parse a \ufeff-prefixed document and asserts the parsed value
round-trips (fails against the pre-fix helper, passes with the
BOM strip).

* fix(auth): read .env as utf-8-sig in the dotenv-vs-shell detector

_remove_env_source() decides whether a credential var lives in ~/.hermes/.env
or the shell by scanning the .env with env_path.read_text(errors="replace") —
no encoding. read_text() with no encoding falls back to the system locale
(cp1252/GBK on Windows) and never strips a BOM.

The canonical .env readers in hermes_cli/config.py all use
encoding="utf-8-sig" precisely because 'users may edit .env in Notepad which
adds one' (a BOM), and doctor.py documents that .env is written as UTF-8
everywhere. This sibling reader diverged: on a Notepad-edited .env the BOM
prefixes the first line, so line.strip().startswith(f"{env_var}=") is False
for the first variable — the detector reports a .env-backed key as a phantom
shell export and prints a misleading 'still set in your shell environment'
hint on .

Match the canonical reader (utf-8-sig + errors=replace). Adds a regression
test with a BOM'd .env.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: finish the missing-encoding sweep — BOM-tolerant reads for user-edited stores

Complements the cherry-picked contributor fixes and closes out the
remaining sites of the 'missing explicit encoding' bug class, which is
now permanently gated by ruff PLW1514 (enabled repo-wide in
pyproject.toml and enforced by the blocking `ruff check .` step in
.github/workflows/lint.yml):

- tools/memory_tool.py: read MEMORY.md/USER.md via utf-8-sig so a
  Notepad BOM never glues U+FEFF onto the first entry (issue #10878,
  PR #10888 by @easyvibecoding — strict-decode contract of
  _read_raw_checked preserved rather than errors="replace", so
  undecodable files still refuse read-modify-write instead of being
  lossily rewritten). Regression tests included.
- tools/skills_tool.py: SKILL.md and skill file reads pinned to
  utf-8-sig + errors="replace" — deterministic across platforms instead
  of the locale fallback proposed in PR #51701 (superseded: falling back
  to cp1252/GBK makes the same skill render differently per host); .env
  reader aligned with the canonical utf-8-sig dialect in hermes_cli/config.py.
- agent/shell_hooks.py, hermes_cli/main.py, gateway/slash_commands.py:
  explicit utf-8 on the remaining fdopen/open text-mode sites flagged by
  the AlexFucuson9 sweep series (#56033 #56940 #65565 #66782 #66791).

Co-authored-by: easyvibecoding <easyvibecoding@users.noreply.github.com>
Co-authored-by: AlexFucuson9 <AlexFucuson9@users.noreply.github.com>
Co-authored-by: flyingdoubleg <wangzhe00zju@gmail.com>
Co-authored-by: LeonSGP43 <cine.dreamer.one@gmail.com>

* test: pin module-level _AUTH_JSON_PATH to tmp store in salvaged windows-encoding test

* feat(lint): close the fdopen + chained-call gaps in the encoding footgun gate

ruff PLW1514 (already enforced repo-wide via the blocking lint step)
covers open()/Path.open()/read_text()/write_text() but NOT os.fdopen —
the exact hole the AlexFucuson9 sweep PRs (#56033 #56940 #65565) kept
patching by hand. Add an fdopen rule to check-windows-footguns.py, which
also runs as a blocking CI step, so a bare text-mode fdopen fails CI.

Also fix a false-negative in the read_text/write_text rule: chained
forms like `read_text()[:4000]` or `read_text().splitlines()` never end
the line with `)` and slipped past the multi-line-call heuristic.
Replace the endswith check with a paren-balance walk (keeps multi-line
calls with encoding= on a continuation line unflagged — verified against
the full tree). This makes the rule the effective standing replacement
for the standalone checker proposed in PR #66669: R1-style coverage now
lives in PLW1514 + this script, both blocking in .github/workflows/lint.yml.

Sabotage-verified: reverting agent/shell_hooks.py's fdopen encoding or
tools/skills_tool.py's read_text encoding now fails the gate.

Co-authored-by: AlexFucuson9 <AlexFucuson9@users.noreply.github.com>
Co-authored-by: Paulo Nascimento <pnascimento9596@gmail.com>

* fix(tests): read and write test files as UTF-8 so the suite runs on Windows

`tests/hermes_cli/test_plugins_cmd.py::TestNoAutoActivation::test_compressor_default_ignores_plugin`
fails on every Windows machine:

    UnicodeDecodeError: 'charmap' codec can't decode byte 0x8f in
    position 47744: character maps to <undefined>

The test reads `run_agent.py` back as text to assert a removed comment is
gone, but called `open()` with no `encoding=`. Python then falls back to
the locale preferred encoding, which is cp1252 on a default Windows
install rather than UTF-8. `run_agent.py` contains nine bytes cp1252
leaves undefined, so the read raises before the assertion is reached. On
Linux and macOS the preferred encoding is UTF-8 and the same line is
fine, which is why CI never caught it.

That one line is the only active failure. The rest of this change closes
the same gap in the files it touches, which `scripts/check-windows-footguns.py`
flags and which the #71014 read_text campaign has been working through
elsewhere in the tree:

- `tests/hermes_cli/test_plugins_cmd.py`: nine bare `write_text`/`read_text`
  calls writing YAML manifests, config and plugin sources
- `tests/tools/test_web_tools_truncate.py`: reads stored extracted web text,
  which is arbitrary content from the internet
- `tests/stress/test_atypical_scenarios.py`: writes and reads worker task
  ids and a barrier file

All three files are now clean under `check-windows-footguns.py`.

Reads go through `Path.read_text(encoding="utf-8")` rather than
`open(...).read()`, which also closes the handle instead of leaving it to
the garbage collector. On Windows a live handle blocks tmpdir cleanup, so
that part is not cosmetic either.

No new test. The repaired test is the regression coverage: it fails
before this change and passes after, on Windows.

* fix(tests): Windows-aware path-list split and UTF-8 progress output in parallel runner

Two Windows bugs in scripts/run_tests_parallel.py:

- --files/--paths/HERMES_TEST_PATHS were split on ':', which shreds
  absolute Windows paths at the drive letter ('C:\repo\tests' ->
  ['C', '\repo\tests']): the drive letter became a phantom discovery
  root and the rooted remainder only resolved by WindowsPath
  re-anchoring it onto repo_root's drive. New _split_pathspec() keeps
  drive-letter colons glued to their path and accepts ';' (os.pathsep)
  on Windows, while ':'-joined lists (CI generate job) keep working.

- With piped stdout (CI, subprocess capture) Windows encodes the
  runner's output as the ANSI code page, so printing the per-file
  progress glyphs raised UnicodeEncodeError inside the executor
  done-callback and every pro…
ma1138569845 pushed a commit to ma1138569845/dechnicAuditor-agent that referenced this pull request Aug 10, 2026
The batch quality gate (NousResearch#81141) now rejects 1-task batches before
schema coercion runs; exercise schema rejection with a valid batch.
ma1138569845 pushed a commit to ma1138569845/dechnicAuditor-agent that referenced this pull request Aug 10, 2026
…81139/NousResearch#81141/NousResearch#81148

Four fix-forwards from the adversarial post-merge audit of the Aug 7
unreviewed merge batch:

- estop (NousResearch#81148): is_engaged() now fails SAFE (engaged) on stat errors;
  the gateway estop gate lets recognized slash commands and replies owned
  by in-flight work (update prompts, clarify, slash-confirm, tool
  approvals, running sessions) through instead of consuming them; new
  gateway /pause [reason|off] command gives messaging-only operators an
  in-band engage/resume path (busy_policy=dispatch so it works mid-run).
- cron monitor mode (NousResearch#81138): execution-mode invariants (monitor x
  no_agent, monitor_script x monitor_url, no_agent-requires-script) now
  have ONE owner (_validate_job_mode_invariants) called from BOTH
  create_job and update_job, so the create-time invariant can no longer
  be silently violated through the update door.
- cron notepad (NousResearch#81139): remove_job now clears the job's notepad rows
  (clear_notepad was dead code -> orphaned KV state forever); clear is
  best-effort and no-ops without creating notepad.db.
- delegation batch gate (NousResearch#81141): template-marker regex narrowed to
  multi-word placeholder shapes only (<feature name>, {file_path}) so
  generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string
  style no longer reject legitimate batches; duplicate-goal rejection
  removed (best-of-N fan-outs are legitimate).
randlee pushed a commit to randlee/hermes-agent that referenced this pull request Aug 11, 2026
The batch quality gate (NousResearch#81141) now rejects 1-task batches before
schema coercion runs; exercise schema rejection with a valid batch.
randlee pushed a commit to randlee/hermes-agent that referenced this pull request Aug 11, 2026
…81139/NousResearch#81141/NousResearch#81148

Four fix-forwards from the adversarial post-merge audit of the Aug 7
unreviewed merge batch:

- estop (NousResearch#81148): is_engaged() now fails SAFE (engaged) on stat errors;
  the gateway estop gate lets recognized slash commands and replies owned
  by in-flight work (update prompts, clarify, slash-confirm, tool
  approvals, running sessions) through instead of consuming them; new
  gateway /pause [reason|off] command gives messaging-only operators an
  in-band engage/resume path (busy_policy=dispatch so it works mid-run).
- cron monitor mode (NousResearch#81138): execution-mode invariants (monitor x
  no_agent, monitor_script x monitor_url, no_agent-requires-script) now
  have ONE owner (_validate_job_mode_invariants) called from BOTH
  create_job and update_job, so the create-time invariant can no longer
  be silently violated through the update door.
- cron notepad (NousResearch#81139): remove_job now clears the job's notepad rows
  (clear_notepad was dead code -> orphaned KV state forever); clear is
  best-effort and no-ops without creating notepad.db.
- delegation batch gate (NousResearch#81141): template-marker regex narrowed to
  multi-word placeholder shapes only (<feature name>, {file_path}) so
  generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string
  style no longer reject legitimate batches; duplicate-goal rejection
  removed (best-of-N fan-outs are legitimate).
blut-agent pushed a commit to blut-agent/hermes-agent-fork that referenced this pull request Aug 11, 2026
The batch quality gate (NousResearch#81141) now rejects 1-task batches before
schema coercion runs; exercise schema rejection with a valid batch.
blut-agent pushed a commit to blut-agent/hermes-agent-fork that referenced this pull request Aug 11, 2026
…81139/NousResearch#81141/NousResearch#81148

Four fix-forwards from the adversarial post-merge audit of the Aug 7
unreviewed merge batch:

- estop (NousResearch#81148): is_engaged() now fails SAFE (engaged) on stat errors;
  the gateway estop gate lets recognized slash commands and replies owned
  by in-flight work (update prompts, clarify, slash-confirm, tool
  approvals, running sessions) through instead of consuming them; new
  gateway /pause [reason|off] command gives messaging-only operators an
  in-band engage/resume path (busy_policy=dispatch so it works mid-run).
- cron monitor mode (NousResearch#81138): execution-mode invariants (monitor x
  no_agent, monitor_script x monitor_url, no_agent-requires-script) now
  have ONE owner (_validate_job_mode_invariants) called from BOTH
  create_job and update_job, so the create-time invariant can no longer
  be silently violated through the update door.
- cron notepad (NousResearch#81139): remove_job now clears the job's notepad rows
  (clear_notepad was dead code -> orphaned KV state forever); clear is
  best-effort and no-ops without creating notepad.db.
- delegation batch gate (NousResearch#81141): template-marker regex narrowed to
  multi-word placeholder shapes only (<feature name>, {file_path}) so
  generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string
  style no longer reject legitimate batches; duplicate-goal rejection
  removed (best-of-N fan-outs are legitimate).
33hodl pushed a commit to 33hodl/hermes-agent that referenced this pull request Aug 12, 2026
The batch quality gate (NousResearch#81141) now rejects 1-task batches before
schema coercion runs; exercise schema rejection with a valid batch.
33hodl pushed a commit to 33hodl/hermes-agent that referenced this pull request Aug 12, 2026
…81139/NousResearch#81141/NousResearch#81148

Four fix-forwards from the adversarial post-merge audit of the Aug 7
unreviewed merge batch:

- estop (NousResearch#81148): is_engaged() now fails SAFE (engaged) on stat errors;
  the gateway estop gate lets recognized slash commands and replies owned
  by in-flight work (update prompts, clarify, slash-confirm, tool
  approvals, running sessions) through instead of consuming them; new
  gateway /pause [reason|off] command gives messaging-only operators an
  in-band engage/resume path (busy_policy=dispatch so it works mid-run).
- cron monitor mode (NousResearch#81138): execution-mode invariants (monitor x
  no_agent, monitor_script x monitor_url, no_agent-requires-script) now
  have ONE owner (_validate_job_mode_invariants) called from BOTH
  create_job and update_job, so the create-time invariant can no longer
  be silently violated through the update door.
- cron notepad (NousResearch#81139): remove_job now clears the job's notepad rows
  (clear_notepad was dead code -> orphaned KV state forever); clear is
  best-effort and no-ops without creating notepad.db.
- delegation batch gate (NousResearch#81141): template-marker regex narrowed to
  multi-word placeholder shapes only (<feature name>, {file_path}) so
  generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string
  style no longer reject legitimate batches; duplicate-goal rejection
  removed (best-of-N fan-outs are legitimate).
SongotenU added a commit to SongotenU/hermes-agent that referenced this pull request Aug 22, 2026
…ain mode)

When any task goal carries the literal token {previous}, the batch runs
SEQUENTIALLY in task order and each occurrence is substituted with the
preceding task's summary — enabling research→draft→review pipelines
without a parent round-trip between steps.

- _batch_is_chain() detection: case-insensitive; JSON snippets, glob
  braces, and f-string braces never match (post-NousResearch#81141 contract holds)
- Sequential branch in _execute_and_aggregate(): per-step interrupt
  checks, progress lines, failure-degrade (failed previous step injects
  a notice so later steps continue without None/exception text)
- tasks param description documents the chain contract for the model
- 5 new tests: detection, sequencing+expansion, failure degrade,
  plain-batch goals never mutated, schema documentation
gabrielcosi pushed a commit to gabrielcosi/home-ops that referenced this pull request Sep 1, 2026
…8.27 ➔ v2026.8.31) (#606)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/gabrielcosi/hermes-agent](https://github.com/NousResearch/hermes-agent) | patch | `v2026.8.27` → `v2026.8.31` |

---

### Release Notes

<details>
<summary>NousResearch/hermes-agent (ghcr.io/gabrielcosi/hermes-agent)</summary>

### [`v2026.8.31`](https://github.com/NousResearch/hermes-agent/releases/tag/v2026.8.31): Hermes Agent v0.21.0 (v2026.8.31)

[Compare Source](https://github.com/NousResearch/hermes-agent/compare/v2026.8.27...v2026.8.31)

##### Hermes Agent v0.21.0 (v2026.8.31)

**Release Date:** August 31, 2026
**Since v0.20.0:** \~5,800 commits · \~2,475 merged PRs · \~5,680 files changed · \~869,000 insertions · \~135,000 deletions · **\~2,100 issues closed** · 760+ contributors

> **The Pantheon Release.** v0.20.0 made Hermes the herald — he spoke, and he carried word to other agents. In v0.21.0 the gods assemble. Bot Mode ships built into the desktop app: a society of named agents with their own faces and group chats, where your bots talk to each other — and to you — like a team, not a toolbox. Around that spine: cron jobs gained memory and continuity so scheduled agents actually learn between runs, subagents can be steered live mid-flight, the MCP surface became a real command center, and the agent can now drive the desktop's own browser. This release rolls up everything from the v0.20.1–v0.20.6 infrastructure patch tags — those windows are fully documented here.

***

##### ✨ Highlights

- **Bot Mode — your agents become a society, built in** — Bot Mode is now a bundled, default-on part of the desktop app: every agent profile gets a name, a deterministic avatar face (with randomize/lock controls), and a place in a shared roster. Create Discord-style group chats where multiple bots and you talk in one room, @&#8203;-mention any bot from the composer, and give rooms names and pictures. Before, "multi-agent" meant plumbing; now it looks like a chat app full of coworkers. ([#&#8203;87886](https://github.com/NousResearch/hermes-agent/pull/87886), [#&#8203;88243](https://github.com/NousResearch/hermes-agent/pull/88243), [#&#8203;89386](https://github.com/NousResearch/hermes-agent/pull/89386), [#&#8203;96726](https://github.com/NousResearch/hermes-agent/pull/96726) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;dokterdok](https://github.com/dokterdok))

- **`hermes peer` — bot-to-bot DMs between your agents** — Any Hermes agent can now message any other by handle, across profiles and gateways, from the CLI or from inside a conversation. Ask your research bot to hand findings to your coding bot and get the reply back where you can read it. Replies land in each agent's canonical Bot Chat, so conversations between agents are durable and inspectable, not fire-and-forget. ([#&#8203;88725](https://github.com/NousResearch/hermes-agent/pull/88725), [#&#8203;88178](https://github.com/NousResearch/hermes-agent/pull/88178), [#&#8203;91487](https://github.com/NousResearch/hermes-agent/pull/91487) — [@&#8203;teknium1](https://github.com/teknium1))

- **Cron jobs that remember** — Scheduled jobs stopped being goldfish. Cron agents now load and update persistent memory like every other agent, `continuity=true` carries each run's output into the next (so a monitor can dedupe against what it already reported), every job gets a durable notepad scratchpad, monitor-mode jobs skip the LLM entirely when nothing changed, and cron output can land in a bot's canonical Bot Chat — where the bot actually responds. Your 9am briefing job now knows what it told you yesterday. ([#&#8203;91447](https://github.com/NousResearch/hermes-agent/pull/91447), [#&#8203;80774](https://github.com/NousResearch/hermes-agent/pull/80774), [#&#8203;81139](https://github.com/NousResearch/hermes-agent/pull/81139), [#&#8203;81138](https://github.com/NousResearch/hermes-agent/pull/81138), [#&#8203;91487](https://github.com/NousResearch/hermes-agent/pull/91487) — [@&#8203;teknium1](https://github.com/teknium1), [@&#8203;smwbev](https://github.com/smwbev))

- **Steer your subagents while they run** — `delegate_task` gained live orchestration: list running children, steer one mid-flight with a course correction, or stop it early and keep the partial result. Add optional JSON-schema validation on child outputs, per-delegation cost surfaced in results, and raised defaults (250 iterations, 10 concurrent children) — delegation went from fire-and-pray to actually managed parallel work. ([#&#8203;85232](https://github.com/NousResearch/hermes-agent/pull/85232), [#&#8203;81144](https://github.com/NousResearch/hermes-agent/pull/81144), [#&#8203;81142](https://github.com/NousResearch/hermes-agent/pull/81142), [#&#8203;86506](https://github.com/NousResearch/hermes-agent/pull/86506), [#&#8203;86745](https://github.com/NousResearch/hermes-agent/pull/86745) — [@&#8203;teknium1](https://github.com/teknium1))

- **The MCP command center** — MCP servers and the catalog merged into one coherent desktop page with drag-in "paste anything" import, background health checks that nudge you to re-auth before a tool call fails, a fleet cost/usage overlay showing schema token estimates and 30-day usage per server, and `hermes://` deep links that install an MCP server with explicit confirmation. Managing twenty MCP servers used to be config-file archaeology; now it's a dashboard. ([#&#8203;87525](https://github.com/NousResearch/hermes-agent/pull/87525), [#&#8203;87572](https://github.com/NousResearch/hermes-agent/pull/87572), [#&#8203;87576](https://github.com/NousResearch/hermes-agent/pull/87576), [#&#8203;87579](https://github.com/NousResearch/hermes-agent/pull/87579), [#&#8203;87581](https://github.com/NousResearch/hermes-agent/pull/87581) — [@&#8203;teknium1](https://github.com/teknium1))

- **A CLI power wave** — Ctrl+P opens a fuzzy command palette, the `/model` picker filters as you type, `/status` shows reasoning mode, pending approvals, and context usage, and the status bar can display live cache-hit %, latency, and tokens/sec with per-field toggles. Plus: a global emergency stop, session pin/unpin, rotating task-oriented composer placeholders — and Ghostty-level **terminal pets**, because a companion should have a companion. ([#&#8203;90730](https://github.com/NousResearch/hermes-agent/pull/90730), [#&#8203;90717](https://github.com/NousResearch/hermes-agent/pull/90717), [#&#8203;90745](https://github.com/NousResearch/hermes-agent/pull/90745), [#&#8203;98250](https://github.com/NousResearch/hermes-agent/pull/98250), [#&#8203;98282](https://github.com/NousResearch/hermes-agent/pull/98282), [#&#8203;97666](https://github.com/NousResearch/hermes-agent/pull/97666) — [@&#8203;teknium1](https://github.com/teknium1), and salvaged community work)

- **The agent drives the desktop's browser** — The in-app browser stopped being a window the agent could only look at: Hermes now navigates, clicks, and reads it directly, and pages can be popped out to your system browser with full link context menus. Ask it to walk a docs site or debug a web app and watch it happen inside your own app. ([#&#8203;90197](https://github.com/NousResearch/hermes-agent/pull/90197), [#&#8203;89366](https://github.com/NousResearch/hermes-agent/pull/89366) — [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;ethernet8023](https://github.com/ethernet8023))

- **Six new providers and a model catalog wave** — Meta Model API (Muse Spark) arrives as a built-in provider, alongside CommandCode, Tencent TokenPlan, Nebius Token Factory, Ramp Router, and Actual Computer. The catalogs picked up GLM-5.3-Flash, qwen3.8-max/flash, Gemini 3.7 Flash, MiniMax M3 free, and Nemotron 3.5 Lightning — and `model_overrides` lets you patch any model's context window or pricing yourself without waiting on a release. ([#&#8203;88565](https://github.com/NousResearch/hermes-agent/pull/88565), [#&#8203;88308](https://github.com/NousResearch/hermes-agent/pull/88308), [#&#8203;97917](https://github.com/NousResearch/hermes-agent/pull/97917), [#&#8203;97916](https://github.com/NousResearch/hermes-agent/pull/97916), [#&#8203;97915](https://github.com/NousResearch/hermes-agent/pull/97915), [#&#8203;85560](https://github.com/NousResearch/hermes-agent/pull/85560) — [@&#8203;teknium1](https://github.com/teknium1) and community)

- **Security hardening across the board** — Protected agent-instruction files (AGENTS.md, skills, memory stores) now always require write approval so a prompt-injected agent can't quietly rewrite its own standing orders. A deep redaction sweep closed secret-leak gaps across terminal errors, `.env` file reads, checkpoints, and ACP logs; the approval system learned Windows destructive commands; and macOS permission grants finally survive updates via a stable TCC signing identity. ([#&#8203;81152](https://github.com/NousResearch/hermes-agent/pull/81152), [#&#8203;80965](https://github.com/NousResearch/hermes-agent/pull/80965), [#&#8203;84428](https://github.com/NousResearch/hermes-agent/pull/84428), [#&#8203;95091](https://github.com/NousResearch/hermes-agent/pull/95091) — [@&#8203;teknium1](https://github.com/teknium1) and community)

***

##### 🏗️ Core Agent & Architecture

##### Providers & Models

- **New providers:** Actual Computer inference ([#&#8203;79644](https://github.com/NousResearch/hermes-agent/pull/79644), salvage of [#&#8203;26491](https://github.com/NousResearch/hermes-agent/issues/26491)), CommandCode with GOAT/Pro/Max plans ([#&#8203;88308](https://github.com/NousResearch/hermes-agent/pull/88308), salvage of [#&#8203;32909](https://github.com/NousResearch/hermes-agent/issues/32909)), Meta Model API (Muse Spark) as a built-in provider plugin ([#&#8203;88565](https://github.com/NousResearch/hermes-agent/pull/88565)), Tencent TokenPlan ([#&#8203;97917](https://github.com/NousResearch/hermes-agent/pull/97917)), Nebius Token Factory ([#&#8203;97916](https://github.com/NousResearch/hermes-agent/pull/97916)), and Ramp Router ([#&#8203;97915](https://github.com/NousResearch/hermes-agent/pull/97915)).
- **Model catalog wave:** qwen3.8-max and qwen3.8-flash ([#&#8203;78024](https://github.com/NousResearch/hermes-agent/pull/78024), [#&#8203;96979](https://github.com/NousResearch/hermes-agent/pull/96979)), Gemini 3.7 Flash ([#&#8203;85526](https://github.com/NousResearch/hermes-agent/pull/85526)), GLM-5.3-Flash across OpenRouter/Nous/z.ai/OpenCode ([#&#8203;95621](https://github.com/NousResearch/hermes-agent/pull/95621), [#&#8203;96293](https://github.com/NousResearch/hermes-agent/pull/96293)), MiniMax M3 + Inkling free SKUs ([#&#8203;96264](https://github.com/NousResearch/hermes-agent/pull/96264)), Nemotron 3.5 Lightning ([#&#8203;84645](https://github.com/NousResearch/hermes-agent/pull/84645)), Meta Muse Spark 1.2 ([#&#8203;88600](https://github.com/NousResearch/hermes-agent/pull/88600)).
- **Per-model metadata overrides** via `model_overrides` config — patch context windows, pricing, or capabilities for any model without waiting on a release ([#&#8203;85560](https://github.com/NousResearch/hermes-agent/pull/85560)).
- **Data-training-tier warnings** — a unified selection-guard registry warns you across every picker surface when a model trains on your data ([#&#8203;85917](https://github.com/NousResearch/hermes-agent/pull/85917)).
- **Pip-installed model providers** discovered via entry points — third parties can ship providers as packages ([#&#8203;85504](https://github.com/NousResearch/hermes-agent/pull/85504), salvage [#&#8203;81419](https://github.com/NousResearch/hermes-agent/issues/81419)).
- **Prompt caching engaged for LiteLLM Claude** on the OpenAI wire ([#&#8203;87517](https://github.com/NousResearch/hermes-agent/pull/87517) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor)) and api.meta.ai routed through the Responses API for caching ([#&#8203;88601](https://github.com/NousResearch/hermes-agent/pull/88601)).
- **Codex GPT context defaults** back to the verified 272K, with explicit -900k picker variants for the large window ([#&#8203;92797](https://github.com/NousResearch/hermes-agent/pull/92797)).

##### Agent Loop & Reliability

- **Stalled-provider recovery** — a stalled stream no longer leaves Desktop silent or burns the retry budget ([#&#8203;87236](https://github.com/NousResearch/hermes-agent/pull/87236) — [@&#8203;fangliquanflq](https://github.com/fangliquanflq)).
- **MoA hardening cluster** — the Mixture-of-Agents facade now survives client rebuilds, stream retries, provider rotation, and fallback/restore without leaking prepared requests to native clients ([#&#8203;90212](https://github.com/NousResearch/hermes-agent/pull/90212) and siblings).
- **Structured-output resilience** — auxiliary calls translate `response_format` for Anthropic wires and retry when a provider rejects structured output ([#&#8203;89589](https://github.com/NousResearch/hermes-agent/pull/89589) — [@&#8203;ethernet8023](https://github.com/ethernet8023)).
- **Compression: lean tail mode** + a compaction recall eval harness to measure what compression actually preserves ([#&#8203;87326](https://github.com/NousResearch/hermes-agent/pull/87326)).
- **Oversized tool results spill to cache** instead of being truncated in sandbox-less sessions ([#&#8203;89028](https://github.com/NousResearch/hermes-agent/pull/89028)).
- **`clarify` asks multiple independent questions in one call** — one form instead of a chain of round-trips ([#&#8203;89467](https://github.com/NousResearch/hermes-agent/pull/89467) — [@&#8203;ethernet8023](https://github.com/ethernet8023)).
- **Verify subsystem** (port from superagent-ai/grok-cli): run-recipe detection + environment manifest so "it works" claims are backed by detected build/test commands ([#&#8203;80686](https://github.com/NousResearch/hermes-agent/pull/80686)).

##### Sessions & State

- **Resumed transcripts never re-append** — `_db_persisted` stamped at row load time ([#&#8203;92539](https://github.com/NousResearch/hermes-agent/pull/92539) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor)).
- **SessionDB context-manager protocol** for leak-free DB lifecycles ([#&#8203;88048](https://github.com/NousResearch/hermes-agent/pull/88048) — [@&#8203;jackulau](https://github.com/jackulau)).
- **Instant session naming** from the opening message, with sticky titles across resume ([#&#8203;81985](https://github.com/NousResearch/hermes-agent/pull/81985) — [@&#8203;OutThisLife](https://github.com/OutThisLife)).
- **Session pin/unpin from the CLI** — durable keep flags ([#&#8203;80761](https://github.com/NousResearch/hermes-agent/pull/80761)).

##### 📱 Messaging Platforms (Gateway)

- **Slack native live cards** — real streaming replies via chat.startStream plus opt-in plan/task cards for tool progress ([#&#8203;85476](https://github.com/NousResearch/hermes-agent/pull/85476)); outbound link-preview suppression across native and relay planes ([#&#8203;95142](https://github.com/NousResearch/hermes-agent/pull/95142) — [@&#8203;benbarclay](https://github.com/benbarclay)).
- **Telegram inline picker** — every command and skill searchable via [@&#8203;botname](https://github.com/botname), bypassing Telegram's command-menu cap ([#&#8203;98317](https://github.com/NousResearch/hermes-agent/pull/98317)).
- **Relay matured** — native static/dynamic plugin initialization ([#&#8203;77915](https://github.com/NousResearch/hermes-agent/pull/77915) — [@&#8203;bbednarski9](https://github.com/bbednarski9)), live-card ops with draft streaming + task cards ([#&#8203;85796](https://github.com/NousResearch/hermes-agent/pull/85796) — [@&#8203;victor-kyriazakos](https://github.com/victor-kyriazakos)), session-span segmentation ([#&#8203;85467](https://github.com/NousResearch/hermes-agent/pull/85467)), voice-note STT restored over the relay lane ([#&#8203;95274](https://github.com/NousResearch/hermes-agent/pull/95274) — [@&#8203;benbarclay](https://github.com/benbarclay)), transport dedupe/fail-fast fixes ([#&#8203;89584](https://github.com/NousResearch/hermes-agent/pull/89584)).
- **Gateway control socket** — fleet consumers query the gateway itself (identify/status), and updaters pause gateways gracefully instead of tree-killing them ([#&#8203;92447](https://github.com/NousResearch/hermes-agent/pull/92447), [#&#8203;95695](https://github.com/NousResearch/hermes-agent/pull/95695)).
- **Selective multiplex profile serving** ([#&#8203;83400](https://github.com/NousResearch/hermes-agent/pull/83400)), per-profile MCP lifecycle RPCs ([#&#8203;86473](https://github.com/NousResearch/hermes-agent/pull/86473)), roster previews showing the latest message ([#&#8203;85905](https://github.com/NousResearch/hermes-agent/pull/85905)), concise background-process notifications by default ([#&#8203;85877](https://github.com/NousResearch/hermes-agent/pull/85877)).
- **Turn-reaper stack dumps** — when the watchdog fires, wedged worker stacks are captured for diagnosis ([#&#8203;86248](https://github.com/NousResearch/hermes-agent/pull/86248)), with loop-watchdog tuning knobs wired end-to-end ([#&#8203;92317](https://github.com/NousResearch/hermes-agent/pull/92317)).
- **Split-delivery bug class closed** — swallowed finals and split deliveries fixed as a class ([#&#8203;79669](https://github.com/NousResearch/hermes-agent/pull/79669) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor), salvages [#&#8203;78558](https://github.com/NousResearch/hermes-agent/issues/78558)).

##### 🖥️ Desktop App

- **Bot Mode built in** — see Highlights. Full sub-catalog: attributed agent-to-agent message cards ([#&#8203;85855](https://github.com/NousResearch/hermes-agent/pull/85855)), sender-side delivery notices ([#&#8203;85888](https://github.com/NousResearch/hermes-agent/pull/85888)), paint-first hydration for instant wakes ([#&#8203;89510](https://github.com/NousResearch/hermes-agent/pull/89510)), editable group names and room pictures ([#&#8203;89371](https://github.com/NousResearch/hermes-agent/pull/89371)), Routines pane ([#&#8203;88731](https://github.com/NousResearch/hermes-agent/pull/88731)), rebuilt on the app design system ([#&#8203;96726](https://github.com/NousResearch/hermes-agent/pull/96726) — [@&#8203;OutThisLife](https://github.com/OutThisLife)).
- **In-app browser the agent can drive** — the agent uses the desktop's browser tab, not just looks at it ([#&#8203;90197](https://github.com/NousResearch/hermes-agent/pull/90197) — [@&#8203;OutThisLife](https://github.com/OutThisLife)), with external-open + link context menus ([#&#8203;89366](https://github.com/NousResearch/hermes-agent/pull/89366)).
- **Detached update hand-off on every OS** — quit → update → reopen with a single shim window; Windows desktop updates no longer park on "Updating Hermes" ([#&#8203;83634](https://github.com/NousResearch/hermes-agent/pull/83634), [#&#8203;90937](https://github.com/NousResearch/hermes-agent/pull/90937), [#&#8203;95897](https://github.com/NousResearch/hermes-agent/pull/95897)).
- **Quality-of-life wave** — HUD snaps to cursor on ⌘⇧G ([#&#8203;83130](https://github.com/NousResearch/hermes-agent/pull/83130)), paste into the composer without focusing it ([#&#8203;84955](https://github.com/NousResearch/hermes-agent/pull/84955)), per-turn duration badges ([#&#8203;87245](https://github.com/NousResearch/hermes-agent/pull/87245)), readable macOS window translucency ([#&#8203;88744](https://github.com/NousResearch/hermes-agent/pull/88744)), Linux launcher entry ([#&#8203;76456](https://github.com/NousResearch/hermes-agent/pull/76456)), Linux keychain auto-detection ([#&#8203;84903](https://github.com/NousResearch/hermes-agent/pull/84903)), cron + blueprint recipes in the sidebar ([#&#8203;85162](https://github.com/NousResearch/hermes-agent/pull/85162)).
- **Send Diagnostics** — error cards can upload a redacted debug bundle with a support handoff ([#&#8203;92020](https://github.com/NousResearch/hermes-agent/pull/92020)).
- **Seq-stamped event replay** — lossless desktop reconnect over WebSocket ([#&#8203;94219](https://github.com/NousResearch/hermes-agent/pull/94219) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor)).
- **God-file decomposition** — the desktop codebase refactored into atomic modules ([#&#8203;89611](https://github.com/NousResearch/hermes-agent/pull/89611) — [@&#8203;OutThisLife](https://github.com/OutThisLife)).

##### 🖥️ CLI & TUI

- See Highlights for the power wave (command palette, fuzzy /model, richer /status, live status-bar metrics, pets).
- **`hermes approval-check`** — dry-run approval verdicts for a command without running it ([#&#8203;81137](https://github.com/NousResearch/hermes-agent/pull/81137)).
- **Session titles in status bars** ([#&#8203;81947](https://github.com/NousResearch/hermes-agent/pull/81947)); subagent model exposed in the auxiliary-models picker ([#&#8203;80463](https://github.com/NousResearch/hermes-agent/pull/80463)).
- **Ctrl+C fixed** — stopped pushing the Kitty keyboard protocol that broke interrupts ([#&#8203;87074](https://github.com/NousResearch/hermes-agent/pull/87074)).

##### 🔧 Tool System & MCP

- **MCP command center** — see Highlights ([#&#8203;87525](https://github.com/NousResearch/hermes-agent/pull/87525) et al.).
- **Interrupted commands no longer poison cwd** — the terminal won't adopt a stale working directory after an interrupt ([#&#8203;85654](https://github.com/NousResearch/hermes-agent/pull/85654) — [@&#8203;ethernet8023](https://github.com/ethernet8023)).
- **Windows rename contention recovery** ([#&#8203;84852](https://github.com/NousResearch/hermes-agent/pull/84852) — [@&#8203;OutThisLife](https://github.com/OutThisLife)); colon-bearing session IDs no longer break sandbox mounts ([#&#8203;93488](https://github.com/NousResearch/hermes-agent/pull/93488), consolidated 6 PRs).
- **Vision output uncapped** — aux vision calls stop clamping max\_tokens ([#&#8203;75253](https://github.com/NousResearch/hermes-agent/pull/75253) — [@&#8203;adikpb](https://github.com/adikpb)).
- **Subagent work protected** — delegate no longer deletes a child's uncommitted work when git inspection fails ([#&#8203;88419](https://github.com/NousResearch/hermes-agent/pull/88419) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor)).

##### 🧩 Skills Ecosystem

- **Productivity skill wave** (salvaged from [@&#8203;community](https://github.com/community) proposals): document-to-action-items, meeting-action-items, email-inbox-triage, github-issue-to-pr, weekly-review-planning, competitor-news-monitor, product-price-monitor, social-media-content-calendar ([#&#8203;81185](https://github.com/NousResearch/hermes-agent/pull/81185), [#&#8203;81749](https://github.com/NousResearch/hermes-agent/pull/81749), [#&#8203;81672](https://github.com/NousResearch/hermes-agent/pull/81672), [#&#8203;81708](https://github.com/NousResearch/hermes-agent/pull/81708), [#&#8203;81936](https://github.com/NousResearch/hermes-agent/pull/81936), [#&#8203;81945](https://github.com/NousResearch/hermes-agent/pull/81945), [#&#8203;81906](https://github.com/NousResearch/hermes-agent/pull/81906), [#&#8203;81942](https://github.com/NousResearch/hermes-agent/pull/81942)).
- **HAR-derived API clients** — watch a website once, then call its hidden API directly with no browser ([#&#8203;70823](https://github.com/NousResearch/hermes-agent/pull/70823)).
- **publish-site** — versioned website publishing to GitHub/Cloudflare/Netlify Pages ([#&#8203;72189](https://github.com/NousResearch/hermes-agent/pull/72189)); **session-librarian** for prompt-driven session management ([#&#8203;84917](https://github.com/NousResearch/hermes-agent/pull/84917)); **blocked-page-recovery** fallback ladder ([#&#8203;84906](https://github.com/NousResearch/hermes-agent/pull/84906)); **merge-reconciler** for neutral multi-agent conflict resolution ([#&#8203;83063](https://github.com/NousResearch/hermes-agent/pull/83063)); Box productivity skill ([#&#8203;85767](https://github.com/NousResearch/hermes-agent/pull/85767)); ast-grep codemods ([#&#8203;80892](https://github.com/NousResearch/hermes-agent/pull/80892)); draw-your-font + simple-english optional skills ([#&#8203;80814](https://github.com/NousResearch/hermes-agent/pull/80814), [#&#8203;80811](https://github.com/NousResearch/hermes-agent/pull/80811)); plan-interrogation (evolved grill-me) ([#&#8203;97831](https://github.com/NousResearch/hermes-agent/pull/97831)).
- **Advisory SKILL.md linter on create** ([#&#8203;81896](https://github.com/NousResearch/hermes-agent/pull/81896)); skills-hub live-repo fallback for missing optional skills ([#&#8203;82780](https://github.com/NousResearch/hermes-agent/pull/82780)).

##### ⏰ Cron, Delegation & Multi-Agent

- **Cron memory + continuity** — see Highlights ([#&#8203;91447](https://github.com/NousResearch/hermes-agent/pull/91447), [#&#8203;80774](https://github.com/NousResearch/hermes-agent/pull/80774)).
- **Monitor-mode jobs** with hash-suppressed change detection ([#&#8203;81138](https://github.com/NousResearch/hermes-agent/pull/81138)); per-job durable notepads ([#&#8203;81139](https://github.com/NousResearch/hermes-agent/pull/81139)); pre-dispatch config validation ([#&#8203;81140](https://github.com/NousResearch/hermes-agent/pull/81140)); acked failure signatures stop re-pinging ([#&#8203;95017](https://github.com/NousResearch/hermes-agent/pull/95017)); per-job reasoning-effort pinning ([#&#8203;91244](https://github.com/NousResearch/hermes-agent/pull/91244)); "Trigger now" executes immediately and safely ([#&#8203;70638](https://github.com/NousResearch/hermes-agent/pull/70638) — [@&#8203;smwbev](https://github.com/smwbev)); model-drift impact surfaced in Desktop ([#&#8203;83266](https://github.com/NousResearch/hermes-agent/pull/83266) — [@&#8203;ctaylor86](https://github.com/ctaylor86)).
- **Live subagent orchestration** — see Highlights ([#&#8203;85232](https://github.com/NousResearch/hermes-agent/pull/85232)); structured-output schemas on delegate\_task ([#&#8203;81144](https://github.com/NousResearch/hermes-agent/pull/81144)); batch-quality validation before spawning ([#&#8203;81141](https://github.com/NousResearch/hermes-agent/pull/81141)); truncation markers on capped children ([#&#8203;86641](https://github.com/NousResearch/hermes-agent/pull/86641)).
- **Kanban hardening** — collision-hotspot flagging ([#&#8203;83428](https://github.com/NousResearch/hermes-agent/pull/83428)), split-brain decision-ownership contract ([#&#8203;83424](https://github.com/NousResearch/hermes-agent/pull/83424)), memory-aware dispatch guard ([#&#8203;88115](https://github.com/NousResearch/hermes-agent/pull/88115)), notify/wake delivery modes ([#&#8203;85487](https://github.com/NousResearch/hermes-agent/pull/85487)).

##### 📊 Observability

- **Model/provider usage reporting** and bounded tool-metrics aggregation land as an observability subsystem ([#&#8203;68881](https://github.com/NousResearch/hermes-agent/pull/68881), [#&#8203;68882](https://github.com/NousResearch/hermes-agent/pull/68882) — [@&#8203;afourniernv](https://github.com/afourniernv)), with lifecycle ops bounded so a wedged pipeline can never block the agent ([#&#8203;83514](https://github.com/NousResearch/hermes-agent/pull/83514) — [@&#8203;victor-kyriazakos](https://github.com/victor-kyriazakos)).

##### 🔒 Security & Reliability

- **Protected instruction files** — writes to AGENTS.md/skills/memory always require approval ([#&#8203;81152](https://github.com/NousResearch/hermes-agent/pull/81152)).
- **Redaction sweep** — emission gaps closed across env-name variants, control-splits, process(list), checkpoints ([#&#8203;80965](https://github.com/NousResearch/hermes-agent/pull/80965)); `.env` reads redacted via file-read detection ([#&#8203;80964](https://github.com/NousResearch/hermes-agent/pull/80964)); terminal exception results + ACP stderr ([#&#8203;81675](https://github.com/NousResearch/hermes-agent/pull/81675), [#&#8203;81686](https://github.com/NousResearch/hermes-agent/pull/81686)); SSH target logging ([#&#8203;88232](https://github.com/NousResearch/hermes-agent/pull/88232)).
- **Windows approval coverage** — destructive Windows commands and paths now trip the approval system ([#&#8203;84428](https://github.com/NousResearch/hermes-agent/pull/84428)).
- **Supply-chain response** — the Blender MCP catalog entry and skill were removed after an upstream compromise ([#&#8203;83404](https://github.com/NousResearch/hermes-agent/pull/83404)); plugin installs get Tier-1 security scanning ([#&#8203;80728](https://github.com/NousResearch/hermes-agent/pull/80728)).
- **macOS TCC identity** — permission grants survive every update via `hermes desktop --setup-tcc-identity` ([#&#8203;95091](https://github.com/NousResearch/hermes-agent/pull/95091)).
- **PKCE cookie fix** — SameSite=None over HTTPS with a matching clear path ([#&#8203;83536](https://github.com/NousResearch/hermes-agent/pull/83536) — [@&#8203;benbarclay](https://github.com/benbarclay)).

##### 🏗️ Infrastructure, CI & Packaging

- **Real-OS CI** — macOS and Windows CI lanes with tests gated by real host OS ([#&#8203;77992](https://github.com/NousResearch/hermes-agent/pull/77992) — [@&#8203;ethernet8023](https://github.com/ethernet8023)); work lanes on 32-core runners ([#&#8203;92009](https://github.com/NousResearch/hermes-agent/pull/92009)); review comments + image builds moved out of the hot CI path ([#&#8203;82668](https://github.com/NousResearch/hermes-agent/pull/82668)).
- **Bootstrap installer** no longer waits on pipe EOF ([#&#8203;90941](https://github.com/NousResearch/hermes-agent/pull/90941) — [@&#8203;OutThisLife](https://github.com/OutThisLife)).

##### 🐛 Notable Bug Fixes

- Desktop session races (Stop→edit/resend, submit ownership) fixed as a cluster ([#&#8203;86594](https://github.com/NousResearch/hermes-agent/pull/86594)); workspace-pane idle flicker ([#&#8203;97513](https://github.com/NousResearch/hermes-agent/pull/97513)); assistant-ui boundary recovery ([#&#8203;81232](https://github.com/NousResearch/hermes-agent/pull/81232)).
- Kanban schema re-creation when a cached DB path loses it ([#&#8203;83619](https://github.com/NousResearch/hermes-agent/pull/83619) — [@&#8203;JoaoMarcos44](https://github.com/JoaoMarcos44)).
- Cron jobs no longer inherit a kanban worker's dispatcher identity ([#&#8203;79657](https://github.com/NousResearch/hermes-agent/pull/79657) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor)); relay-fronted Slack cron delivery ([#&#8203;85340](https://github.com/NousResearch/hermes-agent/pull/85340) — [@&#8203;victor-kyriazakos](https://github.com/victor-kyriazakos)).
- Model-picker serves cached custom-provider catalogs on no-probe opens ([#&#8203;81973](https://github.com/NousResearch/hermes-agent/pull/81973) — [@&#8203;austinpickett](https://github.com/austinpickett)).
- Docker sandbox MEDIA attachments no longer silently drop ([#&#8203;94509](https://github.com/NousResearch/hermes-agent/pull/94509)); desktop binary attachments delivered into sandbox backends ([#&#8203;81717](https://github.com/NousResearch/hermes-agent/pull/81717)).
- Session-hygiene compaction cooldown escalates on repeat failures ([#&#8203;79741](https://github.com/NousResearch/hermes-agent/pull/79741) — [@&#8203;kshitijk4poor](https://github.com/kshitijk4poor)).
- Provider-injected parameter 400s retried instead of aborting the turn ([#&#8203;91643](https://github.com/NousResearch/hermes-agent/pull/91643)).
- …and roughly two thousand more closed issues' worth — this window averaged \~85 merged PRs per day.

##### ↩️ Reverted in this window (not shipping)

- **Model Council mode (/council)** — landed then reverted; not in this release.
- **DCP context engine** — landed then reverted; not in this release.
- **WS-only gateway server ([#&#8203;94245](https://github.com/NousResearch/hermes-agent/issues/94245))** — merged then reverted ([#&#8203;96118](https://github.com/NousResearch/hermes-agent/issues/96118)); FastAPI remains on the desktop boot path. The seq-stamped event replay ([#&#8203;94219](https://github.com/NousResearch/hermes-agent/issues/94219)) DID ship.
- Electron rolled back to 40.10.2; TCC interpreter anchor removed (superseded by the signing-identity approach that shipped).

##### 👥 Contributors

##### Core Team (Nous Research)

- **[@&#8203;teknium1](https://github.com/teknium1)** — release direction, Bot Mode, MCP command center, cron memory, and \~1,340 merged PRs
- **[@&#8203;kshitijk4poor](https://github.com/kshitijk4poor)** (374 PRs) — gateway delivery classes, session persistence, event replay, MoA/caching fixes
- **[@&#8203;OutThisLife](https://github.com/OutThisLife)** (209 PRs) — desktop architecture, Bot Mode UI, in-app browser, update hand-off
- **[@&#8203;ethernet8023](https://github.com/ethernet8023)** (38 PRs) — OS-gated CI lanes, clarify multi-question, tool cwd safety, aux structured-output resilience
- **[@&#8203;benbarclay](https://github.com/benbarclay)** (17 PRs) — relay voice STT, Slack link previews, PKCE
- **[@&#8203;victor-kyriazakos](https://github.com/victor-kyriazakos)** (15 PRs) — relay live cards, observability bounding
- **[@&#8203;rob-maron](https://github.com/rob-maron)**, **[@&#8203;austinpickett](https://github.com/austinpickett)**, **[@&#8203;jquesnelle](https://github.com/jquesnelle)**, **[@&#8203;shannonsands](https://github.com/shannonsands)** — providers, dashboard, model catalogs, and more

##### Top Community Contributors (by merged PR count)

- **[@&#8203;helix4u](https://github.com/helix4u)** (31 PRs) — wake-word capture, session UX, fix wave across desktop and gateway
- **[@&#8203;fangliquanflq](https://github.com/fangliquanflq)** (17 PRs) — stalled-provider recovery and agent-loop resilience
- **[@&#8203;bbednarski9](https://github.com/bbednarski9)** — relay native plugin integration; **[@&#8203;HexLab98](https://github.com/HexLab98)**, **[@&#8203;xxxigm](https://github.com/xxxigm)**, **[@&#8203;afourniernv](https://github.com/afourniernv)** (observability), **[@&#8203;liuhao1024](https://github.com/liuhao1024)**, **[@&#8203;Christopher-Schulze](https://github.com/Christopher-Schulze)**, **[@&#8203;Adolanium](https://github.com/Adolanium)**, **[@&#8203;webtecnica](https://github.com/webtecnica)**, **[@&#8203;smwbev](https://github.com/smwbev)** (cron Trigger-now), **[@&#8203;ctaylor86](https://github.com/ctaylor86)** (cron drift in Desktop), **[@&#8203;JoaoMarcos44](https://github.com/JoaoMarcos44)** (kanban schema recovery), **[@&#8203;jackulau](https://github.com/jackulau)** (SessionDB context manager), **[@&#8203;adikpb](https://github.com/adikpb)** (vision output caps), **[@&#8203;dokterdok](https://github.com/dokterdok)** (Bot Mode unification), and many more.

##### All Contributors

Huge thanks to every one of the 760+ people who contributed code, co-authored fixes, or had their work salvaged into this release:

[@&#8203;03farren](https://github.com/03farren), [@&#8203;0xarkstar](https://github.com/0xarkstar), [@&#8203;0xGr1mm](https://github.com/0xGr1mm), [@&#8203;0xWhiteMage](https://github.com/0xWhiteMage), [@&#8203;100yenadmin](https://github.com/100yenadmin), [@&#8203;1052326311](https://github.com/1052326311), [@&#8203;29206394](https://github.com/29206394), [@&#8203;2ndNatureAI](https://github.com/2ndNatureAI), [@&#8203;3Nya3](https://github.com/3Nya3),
[@&#8203;3x3xX3N0N](https://github.com/3x3xX3N0N), [@&#8203;404Dealer](https://github.com/404Dealer), [@&#8203;4adwentures](https://github.com/4adwentures), [@&#8203;5Hyeons](https://github.com/5Hyeons), [@&#8203;686f6c61](https://github.com/686f6c61), [@&#8203;69k4xmdfm2-blip](https://github.com/69k4xmdfm2-blip), [@&#8203;6ylqq](https://github.com/6ylqq), [@&#8203;75day](https://github.com/75day), [@&#8203;a-espinoza](https://github.com/a-espinoza),
[@&#8203;A-Snegin](https://github.com/A-Snegin), [@&#8203;a-yeyang](https://github.com/a-yeyang), [@&#8203;a0000001](https://github.com/a0000001), [@&#8203;A2chitect](https://github.com/A2chitect), [@&#8203;abitme](https://github.com/abitme), [@&#8203;abundantbeing](https://github.com/abundantbeing), [@&#8203;acewong7](https://github.com/acewong7), [@&#8203;acgh213](https://github.com/acgh213), [@&#8203;adamcap926](https://github.com/adamcap926),
[@&#8203;addelh](https://github.com/addelh), [@&#8203;adikpb](https://github.com/adikpb), [@&#8203;Adolanium](https://github.com/Adolanium), [@&#8203;adurham](https://github.com/adurham), [@&#8203;adybag14-cyber](https://github.com/adybag14-cyber), [@&#8203;afourniernv](https://github.com/afourniernv), [@&#8203;ag9920](https://github.com/ag9920), [@&#8203;ahmadalzaro1](https://github.com/ahmadalzaro1), [@&#8203;Ahmett101](https://github.com/Ahmett101),
[@&#8203;ai-ag2026](https://github.com/ai-ag2026), [@&#8203;AIalliAI](https://github.com/AIalliAI), [@&#8203;aider4ryder](https://github.com/aider4ryder), [@&#8203;Ailirag](https://github.com/Ailirag), [@&#8203;Aintworth](https://github.com/Aintworth), [@&#8203;airo7](https://github.com/airo7), [@&#8203;AiwendilInTheWoods](https://github.com/AiwendilInTheWoods), [@&#8203;akivavh](https://github.com/akivavh), [@&#8203;AL-ZiLLA](https://github.com/AL-ZiLLA),
[@&#8203;Al3xand3r1987](https://github.com/Al3xand3r1987), [@&#8203;albertodepaola](https://github.com/albertodepaola), [@&#8203;aldoeliacim](https://github.com/aldoeliacim), [@&#8203;aleksclark](https://github.com/aleksclark), [@&#8203;AlexanderPrendota](https://github.com/AlexanderPrendota), [@&#8203;alexdev03](https://github.com/alexdev03), [@&#8203;AlexFucuson9](https://github.com/AlexFucuson9),
[@&#8203;AlexGabbia](https://github.com/AlexGabbia), [@&#8203;AlexMnrs](https://github.com/AlexMnrs), [@&#8203;algf](https://github.com/algf), [@&#8203;Allecpu](https://github.com/Allecpu), [@&#8203;allin2](https://github.com/allin2), [@&#8203;alt-glitch](https://github.com/alt-glitch), [@&#8203;amanning3390](https://github.com/amanning3390), [@&#8203;andrexibiza](https://github.com/andrexibiza), [@&#8203;andyst-dev](https://github.com/andyst-dev),
[@&#8203;angel12](https://github.com/angel12), [@&#8203;angeon922-collab](https://github.com/angeon922-collab), [@&#8203;Angriff36](https://github.com/Angriff36), [@&#8203;aniruddhaadak80](https://github.com/aniruddhaadak80), [@&#8203;annguyenNous](https://github.com/annguyenNous), [@&#8203;anuvratrastogi](https://github.com/anuvratrastogi), [@&#8203;Aoshi-Dev](https://github.com/Aoshi-Dev),
[@&#8203;appletechie](https://github.com/appletechie), [@&#8203;arccat-114](https://github.com/arccat-114), [@&#8203;arcimun](https://github.com/arcimun), [@&#8203;ArthurFranckPat](https://github.com/ArthurFranckPat), [@&#8203;aryaxo](https://github.com/aryaxo), [@&#8203;asdasdadhj](https://github.com/asdasdadhj), [@&#8203;ashah360](https://github.com/ashah360), [@&#8203;AshuJoshi](https://github.com/AshuJoshi), [@&#8203;asimons81](https://github.com/asimons81),
[@&#8203;assimovt](https://github.com/assimovt), [@&#8203;austinpickett](https://github.com/austinpickett), [@&#8203;AVW7](https://github.com/AVW7), [@&#8203;Axmr1](https://github.com/Axmr1), [@&#8203;aydnOktay](https://github.com/aydnOktay), [@&#8203;ayushnangia](https://github.com/ayushnangia), [@&#8203;baihemax](https://github.com/baihemax), [@&#8203;bananawalnut](https://github.com/bananawalnut), [@&#8203;Bartok9](https://github.com/Bartok9),
[@&#8203;bashrusakh](https://github.com/bashrusakh), [@&#8203;bbednarski9](https://github.com/bbednarski9), [@&#8203;BearHuddleston](https://github.com/BearHuddleston), [@&#8203;benbarclay](https://github.com/benbarclay), [@&#8203;benfrank241](https://github.com/benfrank241), [@&#8203;beplee](https://github.com/beplee), [@&#8203;bgrablin](https://github.com/bgrablin), [@&#8203;bka9](https://github.com/bka9), [@&#8203;BkashJEE](https://github.com/BkashJEE),
[@&#8203;BlackishGreen33](https://github.com/BlackishGreen33), [@&#8203;BlakeB254](https://github.com/BlakeB254), [@&#8203;blunkjamie-dev](https://github.com/blunkjamie-dev), [@&#8203;BobClawblaw](https://github.com/BobClawblaw), [@&#8203;bradmarshall987](https://github.com/bradmarshall987), [@&#8203;brian717](https://github.com/brian717), [@&#8203;briandevans](https://github.com/briandevans),
[@&#8203;BrianFranco](https://github.com/BrianFranco), [@&#8203;BrinShadewater](https://github.com/BrinShadewater), [@&#8203;brucexu-eth](https://github.com/brucexu-eth), [@&#8203;BrunoBza](https://github.com/BrunoBza), [@&#8203;buffpesos](https://github.com/buffpesos), [@&#8203;burak33bb](https://github.com/burak33bb), [@&#8203;C-EXCITE-STUDIO](https://github.com/C-EXCITE-STUDIO), [@&#8203;c-pompa](https://github.com/c-pompa),
[@&#8203;cadezhou](https://github.com/cadezhou), [@&#8203;calvinnwq](https://github.com/calvinnwq), [@&#8203;capt-marbles](https://github.com/capt-marbles), [@&#8203;carbongotfound](https://github.com/carbongotfound), [@&#8203;carlotestor](https://github.com/carlotestor), [@&#8203;Carry00](https://github.com/Carry00), [@&#8203;cation98](https://github.com/cation98), [@&#8203;ccowan93](https://github.com/ccowan93),
[@&#8203;cedricziel](https://github.com/cedricziel), [@&#8203;cervantesh](https://github.com/cervantesh), [@&#8203;cfdude](https://github.com/cfdude), [@&#8203;Chadmc9889](https://github.com/Chadmc9889), [@&#8203;CharZhou](https://github.com/CharZhou), [@&#8203;chelsealong](https://github.com/chelsealong), [@&#8203;chesterXalan](https://github.com/chesterXalan), [@&#8203;chillerno1](https://github.com/chillerno1),
[@&#8203;Christopher-Schulze](https://github.com/Christopher-Schulze), [@&#8203;chukirk-svg](https://github.com/chukirk-svg), [@&#8203;cicav](https://github.com/cicav), [@&#8203;citizendev9c](https://github.com/citizendev9c), [@&#8203;cj52973](https://github.com/cj52973), [@&#8203;clarkvines](https://github.com/clarkvines), [@&#8203;ClintonEmok](https://github.com/ClintonEmok), [@&#8203;clyu168](https://github.com/clyu168),
[@&#8203;cmoiccool](https://github.com/cmoiccool), [@&#8203;codexbt](https://github.com/codexbt), [@&#8203;coe0718](https://github.com/coe0718), [@&#8203;Cossackx](https://github.com/Cossackx), [@&#8203;coygeek](https://github.com/coygeek), [@&#8203;crazyhulk](https://github.com/crazyhulk), [@&#8203;CrazyWillBear](https://github.com/CrazyWillBear), [@&#8203;criptogus](https://github.com/criptogus), [@&#8203;cryptoyasenka](https://github.com/cryptoyasenka),
[@&#8203;ctaylor86](https://github.com/ctaylor86), [@&#8203;cvillarroel2](https://github.com/cvillarroel2), [@&#8203;cxxCoolStar](https://github.com/cxxCoolStar), [@&#8203;cycorld](https://github.com/cycorld), [@&#8203;dagbs](https://github.com/dagbs), [@&#8203;damadorPL](https://github.com/damadorPL), [@&#8203;DanBennettUK](https://github.com/DanBennettUK), [@&#8203;DanDo385](https://github.com/DanDo385),
[@&#8203;DannyFengTianYu](https://github.com/DannyFengTianYu), [@&#8203;Dannyzen](https://github.com/Dannyzen), [@&#8203;danspicytaco](https://github.com/danspicytaco), [@&#8203;dante32683](https://github.com/dante32683), [@&#8203;darko-mesaros](https://github.com/darko-mesaros), [@&#8203;daromaj](https://github.com/daromaj), [@&#8203;david-bartos-phrase](https://github.com/david-bartos-phrase),
[@&#8203;davidgut1982](https://github.com/davidgut1982), [@&#8203;DavidMetcalfe](https://github.com/DavidMetcalfe), [@&#8203;davidneyravyr](https://github.com/davidneyravyr), [@&#8203;daxro](https://github.com/daxro), [@&#8203;dcdexhome](https://github.com/dcdexhome), [@&#8203;deacon-botdoctor](https://github.com/deacon-botdoctor), [@&#8203;deadczarvc](https://github.com/deadczarvc), [@&#8203;deaneeth](https://github.com/deaneeth),
[@&#8203;DECRUX9812](https://github.com/DECRUX9812), [@&#8203;deepeet-git](https://github.com/deepeet-git), [@&#8203;deniqlab](https://github.com/deniqlab), [@&#8203;DeseretSaint](https://github.com/DeseretSaint), [@&#8203;dhanesh](https://github.com/dhanesh), [@&#8203;Dhruv7201](https://github.com/Dhruv7201), [@&#8203;dhruvkej9](https://github.com/dhruvkej9), [@&#8203;digitalbase](https://github.com/digitalbase),
[@&#8203;DmytroVolodymyrson](https://github.com/DmytroVolodymyrson), [@&#8203;dokterdok](https://github.com/dokterdok), [@&#8203;Dolverin](https://github.com/Dolverin), [@&#8203;dombejar](https://github.com/dombejar), [@&#8203;doncazper](https://github.com/doncazper), [@&#8203;dougatbuck](https://github.com/dougatbuck), [@&#8203;douxy1994](https://github.com/douxy1994), [@&#8203;dpersek](https://github.com/dpersek), [@&#8203;dplush](https://github.com/dplush),
[@&#8203;Drexuxux](https://github.com/Drexuxux), [@&#8203;drissman](https://github.com/drissman), [@&#8203;dromai](https://github.com/dromai), [@&#8203;dtownsel](https://github.com/dtownsel), [@&#8203;duclucky](https://github.com/duclucky), [@&#8203;Dudeman456](https://github.com/Dudeman456), [@&#8203;Dusk1e](https://github.com/Dusk1e), [@&#8203;dvbaecker](https://github.com/dvbaecker), [@&#8203;e-macgregor](https://github.com/e-macgregor),
[@&#8203;EAbaracus](https://github.com/EAbaracus), [@&#8203;eaglezzz0522-cloud](https://github.com/eaglezzz0522-cloud), [@&#8203;Eapwrk](https://github.com/Eapwrk), [@&#8203;easyvibecoding](https://github.com/easyvibecoding), [@&#8203;echoes666](https://github.com/echoes666), [@&#8203;egilewski](https://github.com/egilewski), [@&#8203;ehz0ah](https://github.com/ehz0ah), [@&#8203;ekinnee](https://github.com/ekinnee), [@&#8203;ekzhang](https://github.com/ekzhang),
[@&#8203;elbukott1](https://github.com/elbukott1), [@&#8203;elisam0](https://github.com/elisam0), [@&#8203;elphamale](https://github.com/elphamale), [@&#8203;ElSnacko](https://github.com/ElSnacko), [@&#8203;embwl0x](https://github.com/embwl0x), [@&#8203;emozilla](https://github.com/emozilla), [@&#8203;EMT5320](https://github.com/EMT5320), [@&#8203;EndeavorYen](https://github.com/EndeavorYen), [@&#8203;Enough1122](https://github.com/Enough1122),
[@&#8203;enwaiax](https://github.com/enwaiax), [@&#8203;epeterpanz](https://github.com/epeterpanz), [@&#8203;EpicIsTheOne](https://github.com/EpicIsTheOne), [@&#8203;eric-senyao](https://github.com/eric-senyao), [@&#8203;ernst-bablick](https://github.com/ernst-bablick), [@&#8203;Eros-ITA](https://github.com/Eros-ITA), [@&#8203;erosika](https://github.com/erosika), [@&#8203;ethernet8023](https://github.com/ethernet8023),
[@&#8203;etzelvon](https://github.com/etzelvon), [@&#8203;EvanProgramming](https://github.com/EvanProgramming), [@&#8203;EvenXieWF](https://github.com/EvenXieWF), [@&#8203;explainanalyze](https://github.com/explainanalyze), [@&#8203;f-trycua](https://github.com/f-trycua), [@&#8203;fanfan343](https://github.com/fanfan343), [@&#8203;fangliquanflq](https://github.com/fangliquanflq), [@&#8203;fattchris](https://github.com/fattchris),
[@&#8203;felix-windsor](https://github.com/felix-windsor), [@&#8203;Finn763](https://github.com/Finn763), [@&#8203;flaviovargasbrandao](https://github.com/flaviovargasbrandao), [@&#8203;Fly-onlyone](https://github.com/Fly-onlyone), [@&#8203;flyingdoubleG](https://github.com/flyingdoubleG), [@&#8203;forkercat](https://github.com/forkercat),
[@&#8203;francialisomlimoeiro](https://github.com/francialisomlimoeiro), [@&#8203;francip](https://github.com/francip), [@&#8203;frankmendes1979](https://github.com/frankmendes1979), [@&#8203;fred0m](https://github.com/fred0m), [@&#8203;frendo](https://github.com/frendo), [@&#8203;frizikk](https://github.com/frizikk), [@&#8203;frohsinnllc](https://github.com/frohsinnllc), [@&#8203;Frowtek](https://github.com/Frowtek),
[@&#8203;fukutake1207](https://github.com/fukutake1207), [@&#8203;fyzanshaik](https://github.com/fyzanshaik), [@&#8203;GarlicGo](https://github.com/GarlicGo), [@&#8203;Gateton](https://github.com/Gateton), [@&#8203;georgell-ceo](https://github.com/georgell-ceo), [@&#8203;gfriesen1](https://github.com/gfriesen1), [@&#8203;gigabyte22](https://github.com/gigabyte22), [@&#8203;gigashad](https://github.com/gigashad), [@&#8203;gijoby](https://github.com/gijoby),
[@&#8203;gitong](https://github.com/gitong), [@&#8203;gkd2323c](https://github.com/gkd2323c), [@&#8203;gnanirahulnutakki](https://github.com/gnanirahulnutakki), [@&#8203;GodsBoy](https://github.com/GodsBoy), [@&#8203;gokay-ai](https://github.com/gokay-ai), [@&#8203;goktugvatandas](https://github.com/goktugvatandas), [@&#8203;golldyck](https://github.com/golldyck), [@&#8203;goodchang77](https://github.com/goodchang77), [@&#8203;GottZ](https://github.com/GottZ),
[@&#8203;grahfmusic](https://github.com/grahfmusic), [@&#8203;gregorustar-maker](https://github.com/gregorustar-maker), [@&#8203;greyvito](https://github.com/greyvito), [@&#8203;gsy324](https://github.com/gsy324), [@&#8203;guanla-zz](https://github.com/guanla-zz), [@&#8203;guilhermeartileshubsai](https://github.com/guilhermeartileshubsai), [@&#8203;guilhermeraiuga](https://github.com/guilhermeraiuga),
[@&#8203;h-mascot](https://github.com/h-mascot), [@&#8203;h8hawk](https://github.com/h8hawk), [@&#8203;Haakam21](https://github.com/Haakam21), [@&#8203;Haik-G](https://github.com/Haik-G), [@&#8203;halaprix](https://github.com/halaprix), [@&#8203;Halldrix](https://github.com/Halldrix), [@&#8203;handnewb](https://github.com/handnewb), [@&#8203;Hangzian](https://github.com/Hangzian), [@&#8203;hanhvs](https://github.com/hanhvs), [@&#8203;hansai-art](https://github.com/hansai-art),
[@&#8203;HAOWANG116](https://github.com/HAOWANG116), [@&#8203;HarishDarko](https://github.com/HarishDarko), [@&#8203;hbentel](https://github.com/hbentel), [@&#8203;helix4u](https://github.com/helix4u), [@&#8203;HenryGHJ](https://github.com/HenryGHJ), [@&#8203;hermias1](https://github.com/hermias1), [@&#8203;HexLab98](https://github.com/HexLab98), [@&#8203;hillimited](https://github.com/hillimited), [@&#8203;Hjharris1](https://github.com/Hjharris1),
[@&#8203;hkfiberlaser-svg](https://github.com/hkfiberlaser-svg), [@&#8203;honor2030](https://github.com/honor2030), [@&#8203;howdeploy](https://github.com/howdeploy), [@&#8203;hsearcy](https://github.com/hsearcy), [@&#8203;huklaa](https://github.com/huklaa), [@&#8203;hustwkr](https://github.com/hustwkr), [@&#8203;hutao562](https://github.com/hutao562), [@&#8203;hxwvaa](https://github.com/hxwvaa), [@&#8203;IAvecilla](https://github.com/IAvecilla),
[@&#8203;icemeng](https://github.com/icemeng), [@&#8203;infinitycrew39](https://github.com/infinitycrew39), [@&#8203;infocentr](https://github.com/infocentr), [@&#8203;InphinitiZ](https://github.com/InphinitiZ), [@&#8203;insane66613](https://github.com/insane66613), [@&#8203;Inspired-by-Atmosphere](https://github.com/Inspired-by-Atmosphere), [@&#8203;intelac](https://github.com/intelac),
[@&#8203;intellectronica](https://github.com/intellectronica), [@&#8203;isak-ialogics](https://github.com/isak-ialogics), [@&#8203;ishanparihar](https://github.com/ishanparihar), [@&#8203;isheng-eqi](https://github.com/isheng-eqi), [@&#8203;Ishman82](https://github.com/Ishman82), [@&#8203;iskysun96](https://github.com/iskysun96), [@&#8203;iso2kx](https://github.com/iso2kx), [@&#8203;itsflownium](https://github.com/itsflownium),
[@&#8203;izumi0uu](https://github.com/izumi0uu), [@&#8203;Jaaneek](https://github.com/Jaaneek), [@&#8203;Jackal991](https://github.com/Jackal991), [@&#8203;jackijianxa](https://github.com/jackijianxa), [@&#8203;jackoconner45](https://github.com/jackoconner45), [@&#8203;jackulau](https://github.com/jackulau), [@&#8203;jaimedhenriques](https://github.com/jaimedhenriques), [@&#8203;james47kjv](https://github.com/james47kjv),
[@&#8203;jbagdonas](https://github.com/jbagdonas), [@&#8203;jcjc81](https://github.com/jcjc81), [@&#8203;jdgg777](https://github.com/jdgg777), [@&#8203;jeeves-assistant](https://github.com/jeeves-assistant), [@&#8203;jeff-mettel](https://github.com/jeff-mettel), [@&#8203;Jefftree](https://github.com/Jefftree), [@&#8203;JElfferich](https://github.com/JElfferich), [@&#8203;jeremyrandria-debug](https://github.com/jeremyrandria-debug),
[@&#8203;JinUltimate1995](https://github.com/JinUltimate1995), [@&#8203;jirathip-k](https://github.com/jirathip-k), [@&#8203;jmmaloney4](https://github.com/jmmaloney4), [@&#8203;JoaoMarcos44](https://github.com/JoaoMarcos44), [@&#8203;joe-rodgers](https://github.com/joe-rodgers), [@&#8203;joe050860](https://github.com/joe050860), [@&#8203;John-Lussier](https://github.com/John-Lussier),
[@&#8203;Johnny-xuan](https://github.com/Johnny-xuan), [@&#8203;johnrazmus](https://github.com/johnrazmus), [@&#8203;johnsonAyo](https://github.com/johnsonAyo), [@&#8203;jonpol01](https://github.com/jonpol01), [@&#8203;JonthanaHanh](https://github.com/JonthanaHanh), [@&#8203;JoshPaulie](https://github.com/JoshPaulie), [@&#8203;Jreevo](https://github.com/Jreevo), [@&#8203;jtstothard](https://github.com/jtstothard),
[@&#8203;Julientalbot](https://github.com/Julientalbot), [@&#8203;justcarlosm](https://github.com/justcarlosm), [@&#8203;justinbowes](https://github.com/justinbowes), [@&#8203;justinjohnson25600](https://github.com/justinjohnson25600), [@&#8203;jwtor7](https://github.com/jwtor7), [@&#8203;k0rnacki](https://github.com/k0rnacki), [@&#8203;kadiratesdev](https://github.com/kadiratesdev),
[@&#8203;Kailigithub](https://github.com/Kailigithub), [@&#8203;kaishi00](https://github.com/kaishi00), [@&#8203;KarateWilly](https://github.com/KarateWilly), [@&#8203;kas-cor](https://github.com/kas-cor), [@&#8203;katie-lpd](https://github.com/katie-lpd), [@&#8203;Kavyrocom](https://github.com/Kavyrocom), [@&#8203;KBANTH](https://github.com/KBANTH), [@&#8203;kchernev](https://github.com/kchernev), [@&#8203;KeaneYan](https://github.com/KeaneYan),
[@&#8203;kernel-t1](https://github.com/kernel-t1), [@&#8203;KeroZelvin](https://github.com/KeroZelvin), [@&#8203;kerpopule](https://github.com/kerpopule), [@&#8203;KHALIDagara](https://github.com/KHALIDagara), [@&#8203;KhanCold](https://github.com/KhanCold), [@&#8203;khanhngoo](https://github.com/khanhngoo), [@&#8203;KIAgent01](https://github.com/KIAgent01), [@&#8203;kim-miram](https://github.com/kim-miram), [@&#8203;kimyxx](https://github.com/kimyxx),
[@&#8203;Kinkoolino-Hermes](https://github.com/Kinkoolino-Hermes), [@&#8203;kinsolee](https://github.com/kinsolee), [@&#8203;kitsonk](https://github.com/kitsonk), [@&#8203;klaus765](https://github.com/klaus765), [@&#8203;koltyj](https://github.com/koltyj), [@&#8203;konsisumer](https://github.com/konsisumer), [@&#8203;kronexoi](https://github.com/kronexoi), [@&#8203;krunkosaurus](https://github.com/krunkosaurus),
[@&#8203;kshitijk4poor](https://github.com/kshitijk4poor), [@&#8203;kudapara](https://github.com/kudapara), [@&#8203;kvnloo](https://github.com/kvnloo), [@&#8203;kweiner](https://github.com/kweiner), [@&#8203;kyssta-exe](https://github.com/kyssta-exe), [@&#8203;Kyzcreig](https://github.com/Kyzcreig), [@&#8203;laithrw](https://github.com/laithrw), [@&#8203;lakshyaag-tavily](https://github.com/lakshyaag-tavily), [@&#8203;landaun](https://github.com/landaun),
[@&#8203;laulopezreal](https://github.com/laulopezreal), [@&#8203;laviesony](https://github.com/laviesony), [@&#8203;lazy-idler](https://github.com/lazy-idler), [@&#8203;LBeghini](https://github.com/LBeghini), [@&#8203;leeclouddragon](https://github.com/leeclouddragon), [@&#8203;Leegenux](https://github.com/Leegenux), [@&#8203;LemonSchneid](https://github.com/LemonSchneid), [@&#8203;LeonardoLGDS](https://github.com/LeonardoLGDS),
[@&#8203;leonphull](https://github.com/leonphull), [@&#8203;LeonSGP43](https://github.com/LeonSGP43), [@&#8203;lepetitprince716-prog](https://github.com/lepetitprince716-prog), [@&#8203;Lesnak1](https://github.com/Lesnak1), [@&#8203;lesterlxt](https://github.com/lesterlxt), [@&#8203;lesyuk](https://github.com/lesyuk), [@&#8203;lEWFkRAD](https://github.com/lEWFkRAD), [@&#8203;lextiz](https://github.com/lextiz), [@&#8203;lgy1027](https://github.com/lgy1027),
[@&#8203;Lidang-Jiang](https://github.com/Lidang-Jiang), [@&#8203;lilShawtty-byte](https://github.com/lilShawtty-byte), [@&#8203;lin-hongkuan](https://github.com/lin-hongkuan), [@&#8203;liuhao1024](https://github.com/liuhao1024), [@&#8203;liusencomic-cyber](https://github.com/liusencomic-cyber), [@&#8203;lkz-de](https://github.com/lkz-de), [@&#8203;loafoe](https://github.com/loafoe), [@&#8203;locker95](https://github.com/locker95),
[@&#8203;LordMelkor](https://github.com/LordMelkor), [@&#8203;lorzl](https://github.com/lorzl), [@&#8203;lost9999](https://github.com/lost9999), [@&#8203;loulanyue](https://github.com/loulanyue), [@&#8203;LovePlayCode](https://github.com/LovePlayCode), [@&#8203;luckygreen](https://github.com/luckygreen), [@&#8203;lukeroberts](https://github.com/lukeroberts), [@&#8203;luoxiao6645](https://github.com/luoxiao6645), [@&#8203;luxles](https://github.com/luxles),
[@&#8203;m1k3s0](https://github.com/m1k3s0), [@&#8203;Mabolla](https://github.com/Mabolla), [@&#8203;MagMueller](https://github.com/MagMueller), [@&#8203;magnus919](https://github.com/magnus919), [@&#8203;magnuslundstedt](https://github.com/magnuslundstedt), [@&#8203;MaheshBhushan](https://github.com/MaheshBhushan), [@&#8203;MarcoFernstaedt](https://github.com/MarcoFernstaedt), [@&#8203;mariobgsp](https://github.com/mariobgsp),
[@&#8203;marketing2981](https://github.com/marketing2981), [@&#8203;markmcd](https://github.com/markmcd), [@&#8203;markmnl](https://github.com/markmnl), [@&#8203;MarkVLK](https://github.com/MarkVLK), [@&#8203;marzukia](https://github.com/marzukia), [@&#8203;Mat-London](https://github.com/Mat-London), [@&#8203;matsvarn](https://github.com/matsvarn), [@&#8203;mattprusak](https://github.com/mattprusak), [@&#8203;MaximCrabbe](https://github.com/MaximCrabbe),
[@&#8203;maxmilian](https://github.com/maxmilian), [@&#8203;mehmetkr-31](https://github.com/mehmetkr-31), [@&#8203;Mengchee118](https://github.com/Mengchee118), [@&#8203;menhguin](https://github.com/menhguin), [@&#8203;metamindedu](https://github.com/metamindedu), [@&#8203;michaelHMK](https://github.com/michaelHMK), [@&#8203;michaelsam94](https://github.com/michaelsam94), [@&#8203;milnerrad](https://github.com/milnerrad),
[@&#8203;MindDragonLabs](https://github.com/MindDragonLabs), [@&#8203;misterdas](https://github.com/misterdas), [@&#8203;mjolley9](https://github.com/mjolley9), [@&#8203;mmcallister8](https://github.com/mmcallister8), [@&#8203;mmcclean-aws](https://github.com/mmcclean-aws), [@&#8203;mmchuangyt-ai](https://github.com/mmchuangyt-ai), [@&#8203;moisesvalero](https://github.com/moisesvalero), [@&#8203;mollusk](https://github.com/mollusk),
[@&#8203;monerostar](https://github.com/monerostar), [@&#8203;Morad37](https://github.com/Morad37), [@&#8203;mrkillbob](https://github.com/mrkillbob), [@&#8203;mrmixx-max](https://github.com/mrmixx-max), [@&#8203;mrsucesso](https://github.com/mrsucesso), [@&#8203;MrTheSoulz](https://github.com/MrTheSoulz), [@&#8203;MustafaK99](https://github.com/MustafaK99), [@&#8203;myk0la-b](https://github.com/myk0la-b), [@&#8203;mzkarami](https://github.com/mzkarami),
[@&#8203;n-leezy](https://github.com/n-leezy), [@&#8203;n1majne3](https://github.com/n1majne3), [@&#8203;NaMinhyeok](https://github.com/NaMinhyeok), [@&#8203;nanami7777777](https://github.com/nanami7777777), [@&#8203;nankingjing](https://github.com/nankingjing), [@&#8203;natebransc](https://github.com/natebransc), [@&#8203;nateEc](https://github.com/nateEc), [@&#8203;Navlem](https://github.com/Navlem), [@&#8203;nbxuhk](https://github.com/nbxuhk),
[@&#8203;nductien](https://github.com/nductien), [@&#8203;Ne0teric](https://github.com/Ne0teric), [@&#8203;NealZhouPanda](https://github.com/NealZhouPanda), [@&#8203;necoweb3](https://github.com/necoweb3), [@&#8203;negroni334](https://github.com/negroni334), [@&#8203;nftpoetrist](https://github.com/nftpoetrist), [@&#8203;nicochase](https://github.com/nicochase), [@&#8203;Nicolas-Formenton](https://github.com/Nicolas-Formenton),
[@&#8203;nicolasdmolina](https://github.com/nicolasdmolina), [@&#8203;nikitaBarkov](https://github.com/nikitaBarkov), [@&#8203;NikolaRHristov](https://github.com/NikolaRHristov), [@&#8203;noahingh](https://github.com/noahingh), [@&#8203;nolanchic](https://github.com/nolanchic), [@&#8203;NorethSea](https://github.com/NorethSea), [@&#8203;notkisk](https://github.com/notkisk), [@&#8203;notwitcheer](https://github.com/notwitcheer),
[@&#8203;NousResearch](https://github.com/NousResearch), [@&#8203;null-runner](https://github.com/null-runner), [@&#8203;ojassharma7](https://github.com/ojassharma7), [@&#8203;oliver-mee](https://github.com/oliver-mee), [@&#8203;olympusbuildz](https://github.com/olympusbuildz), [@&#8203;OmarB97](https://github.com/OmarB97), [@&#8203;ooiuuii](https://github.com/ooiuuii), [@&#8203;openclaww-xz](https://github.com/openclaww-xz),
[@&#8203;opti-josh-holt](https://github.com/opti-josh-holt), [@&#8203;osgeek90](https://github.com/osgeek90), [@&#8203;ousiaresearch](https://github.com/ousiaresearch), [@&#8203;OutThisLife](https://github.com/OutThisLife), [@&#8203;Owen-narcissus](https://github.com/Owen-narcissus), [@&#8203;paoloantinori](https://github.com/paoloantinori), [@&#8203;Parker-Fawcett](https://github.com/Parker-Fawcett),
[@&#8203;pasevin](https://github.com/pasevin), [@&#8203;pasmud](https://github.com/pasmud), [@&#8203;PaulBlackSwan](https://github.com/PaulBlackSwan), [@&#8203;paultaki](https://github.com/paultaki), [@&#8203;peetteerr](https://github.com/peetteerr), [@&#8203;pefontana](https://github.com/pefontana), [@&#8203;Per0-1](https://github.com/Per0-1), [@&#8203;pierrenode](https://github.com/pierrenode), [@&#8203;PINKIIILQWQ](https://github.com/PINKIIILQWQ),
[@&#8203;pittosporum-seu](https://github.com/pittosporum-seu), [@&#8203;pju-hoge](https://github.com/pju-hoge), [@&#8203;plcunha](https://github.com/plcunha), [@&#8203;Pluviobyte](https://github.com/Pluviobyte), [@&#8203;pmos69](https://github.com/pmos69), [@&#8203;pnascimento9596](https://github.com/pnascimento9596), [@&#8203;poisdahl](https://github.com/poisdahl), [@&#8203;potatosalad](https://github.com/potatosalad),
[@&#8203;prashantjain25](https://github.com/prashantjain25), [@&#8203;PRATHAMESH75](https://github.com/PRATHAMESH75), [@&#8203;professorpalmer](https://github.com/professorpalmer), [@&#8203;projetsjsl](https://github.com/projetsjsl), [@&#8203;protas-box](https://github.com/protas-box), [@&#8203;qazasdsdqaza](https://github.com/qazasdsdqaza), [@&#8203;QDung210](https://github.com/QDung210),
[@&#8203;qixuancao](https://github.com/qixuancao), [@&#8203;QuarkAssistant](https://github.com/QuarkAssistant), [@&#8203;quocanh261997](https://github.com/quocanh261997), [@&#8203;ragingbulld](https://github.com/ragingbulld), [@&#8203;rainbowgore](https://github.com/rainbowgore), [@&#8203;rapsealk](https://github.com/rapsealk), [@&#8203;Raven26-VooDoo](https://github.com/Raven26-VooDoo),
[@&#8203;RaviTharuma](https://github.com/RaviTharuma), [@&#8203;RayCharlizard](https://github.com/RayCharlizard), [@&#8203;razultull](https://github.com/razultull), [@&#8203;re-ITRT](https://github.com/re-ITRT), [@&#8203;Reksely](https://github.com/Reksely), [@&#8203;RelaxJonh](https://github.com/RelaxJonh), [@&#8203;repfigit](https://github.com/repfigit), [@&#8203;RGerrish](https://github.com/RGerrish), [@&#8203;RibatTRW](https://github.com/RibatTRW),
[@&#8203;RichardGuan1](https://github.com/RichardGuan1), [@&#8203;RichardHojunJang](https://github.com/RichardHojunJang), [@&#8203;richardhowes](https://github.com/richardhowes), [@&#8203;RickyYii](https://github.com/RickyYii), [@&#8203;rikkarth](https://github.com/rikkarth), [@&#8203;rille111](https://github.com/rille111), [@&#8203;Ringo6107](https://github.com/Ringo6107), [@&#8203;rjhilgefort](https://github.com/rjhilgefort),
[@&#8203;rjvandeve](https://github.com/rjvandeve), [@&#8203;rkfshakti](https://github.com/rkfshakti), [@&#8203;rlaope](https://github.com/rlaope), [@&#8203;Rmohid](https://github.com/Rmohid), [@&#8203;rob-maron](https://github.com/rob-maron), [@&#8203;rodrigogs](https://github.com/rodrigogs), [@&#8203;royalaid](https://github.com/royalaid), [@&#8203;royzhrxy-glitch](https://github.com/royzhrxy-glitch), [@&#8203;rroverin](https://github.com/rroverin),
[@&#8203;rshi0212](https://github.com/rshi0212), [@&#8203;rsk-731](https://github.com/rsk-731), [@&#8203;rtcopenclawgh](https://github.com/rtcopenclawgh), [@&#8203;ruangraung](https://github.com/ruangraung), [@&#8203;rudrakshchahal](https://github.com/rudrakshchahal), [@&#8203;ruochu88s](https://github.com/ruochu88s), [@&#8203;rweddle](https://github.com/rweddle), [@&#8203;ryankhart](https://github.com/ryankhart), [@&#8203;S-Claw](https://github.com/S-Claw),
[@&#8203;Sahil-SS9](https://github.com/Sahil-SS9), [@&#8203;salch-cred](https://github.com/salch-cred), [@&#8203;sam7894604](https://github.com/sam7894604), [@&#8203;samclams](https://github.com/samclams), [@&#8203;saralilyb](https://github.com/saralilyb), [@&#8203;sashmatash](https://github.com/sashmatash), [@&#8203;sasquatch9818](https://github.com/sasquatch9818), [@&#8203;satotakumi](https://github.com/satotakumi),
[@&#8203;ScaleLeanChris](https://github.com/ScaleLeanChris), [@&#8203;SeashoreShi](https://github.com/SeashoreShi), [@&#8203;serefyarar](https://github.com…
melon-xf added a commit to melon-xf/hermes-agent that referenced this pull request Sep 3, 2026
The batch quality gate (NousResearch#81141) now rejects 1-task batches before
schema coercion runs; exercise schema rejection with a valid batch.
melon-xf added a commit to melon-xf/hermes-agent that referenced this pull request Sep 3, 2026
…81139/NousResearch#81141/NousResearch#81148

Four fix-forwards from the adversarial post-merge audit of the Aug 7
unreviewed merge batch:

- estop (NousResearch#81148): is_engaged() now fails SAFE (engaged) on stat errors;
  the gateway estop gate lets recognized slash commands and replies owned
  by in-flight work (update prompts, clarify, slash-confirm, tool
  approvals, running sessions) through instead of consuming them; new
  gateway /pause [reason|off] command gives messaging-only operators an
  in-band engage/resume path (busy_policy=dispatch so it works mid-run).
- cron monitor mode (NousResearch#81138): execution-mode invariants (monitor x
  no_agent, monitor_script x monitor_url, no_agent-requires-script) now
  have ONE owner (_validate_job_mode_invariants) called from BOTH
  create_job and update_job, so the create-time invariant can no longer
  be silently violated through the update door.
- cron notepad (NousResearch#81139): remove_job now clears the job's notepad rows
  (clear_notepad was dead code -> orphaned KV state forever); clear is
  best-effort and no-ops without creating notepad.db.
- delegation batch gate (NousResearch#81141): template-marker regex narrowed to
  multi-word placeholder shapes only (<feature name>, {file_path}) so
  generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string
  style no longer reject legitimate batches; duplicate-goal rejection
  removed (best-of-N fan-outs are legitimate).
smfworks pushed a commit to smfworks/hermes-agent that referenced this pull request Sep 7, 2026
The batch quality gate (NousResearch#81141) now rejects 1-task batches before
schema coercion runs; exercise schema rejection with a valid batch.
smfworks pushed a commit to smfworks/hermes-agent that referenced this pull request Sep 7, 2026
…81139/NousResearch#81141/NousResearch#81148

Four fix-forwards from the adversarial post-merge audit of the Aug 7
unreviewed merge batch:

- estop (NousResearch#81148): is_engaged() now fails SAFE (engaged) on stat errors;
  the gateway estop gate lets recognized slash commands and replies owned
  by in-flight work (update prompts, clarify, slash-confirm, tool
  approvals, running sessions) through instead of consuming them; new
  gateway /pause [reason|off] command gives messaging-only operators an
  in-band engage/resume path (busy_policy=dispatch so it works mid-run).
- cron monitor mode (NousResearch#81138): execution-mode invariants (monitor x
  no_agent, monitor_script x monitor_url, no_agent-requires-script) now
  have ONE owner (_validate_job_mode_invariants) called from BOTH
  create_job and update_job, so the create-time invariant can no longer
  be silently violated through the update door.
- cron notepad (NousResearch#81139): remove_job now clears the job's notepad rows
  (clear_notepad was dead code -> orphaned KV state forever); clear is
  best-effort and no-ops without creating notepad.db.
- delegation batch gate (NousResearch#81141): template-marker regex narrowed to
  multi-word placeholder shapes only (<feature name>, {file_path}) so
  generics (Vec<T>), HTML tags, JSON snippets, glob braces and f-string
  style no longer reject legitimate batches; duplicate-goal rejection
  removed (best-of-N fan-outs are legitimate).
adurham added a commit to adurham/hermes-agent that referenced this pull request Sep 25, 2026
…ion contracts

All six failures here fail IDENTICALLY at the fork's own pre-merge tip
(14f7219) — long-standing stale seams, not merge damage. Verified at that
baseline before touching anything.

test_mcp_dynamic_discovery.py (3 failures) — every assertion hardcoded the
upstream-shaped "mcp__<server>__<tool>" literal, but the fork's registered-name
convention is deliberately bare "<server>_<tool>" (9477c3e; FORK.md lists it
as "a deliberate, permanent fork convention"). Production exposes
mcp_registered_tool_name() for exactly this; the file's own newer tests already
use bare names. Replaced all 18 registered-name literals with calls to that
function, so the tests track the convention instead of re-encoding it.

test_async_delegation.py (3 failures):
* batch_runs_as_one_unit — goals were "a"/"b"/"c", which the batch-quality
  validation (delegate_tool_tasks._MIN_BATCH_GOAL_LEN = 10, upstream NousResearch#81141,
  present at all three baselines) rejects before spawning: the call returned
  {"error": "Task 0 goal is too short..."} instead of a dispatch handle.
  Real goals now, asserted throughout.
* passes_progress_fn_to_async_registry — asserted the handle's delegation_id
  equals the fake dispatcher's return ("deleg_progress"). The handle carries the
  LIVE-TRANSCRIPT id so it matches cache/delegation/live/<id>/
  (delegate_tool_dispatch.py:517-520); the fake's return is only used when there
  is no live id. The progress_fn contract the test exists for — token/in_tool
  wiring — is unchanged and still asserted in full.
* stalled_batch_is_interrupted_then_finalized — asserted the literal "stalled"
  in the user-facing error text. _stalled_error_text deliberately keeps worker
  internals out of that string; the machine-readable signal is status="stalled"
  plus the structured stall_* metadata. Now asserts the real text plus
  stall_phase/stalled_after_quiet_seconds, which is a STRONGER check.

70 passed (was 3 failed / 67 passed); test_mcp_dynamic_discovery 7 passed 1 skipped.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant